CVE-2005-4840: Buffer Overflow
The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within Internet Explorer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4840?
CVE-2005-4840 has a severity rating of medium due to its potential to cause a denial of service.
How do I fix CVE-2005-4840?
To mitigate CVE-2005-4840, users should avoid using Internet Explorer 6 and upgrade to a more secure browser.
Which software is affected by CVE-2005-4840?
CVE-2005-4840 affects the Outlook Express Address Book control when used with Internet Explorer 6.
Can CVE-2005-4840 be exploited remotely?
Yes, CVE-2005-4840 can be exploited remotely by attackers to trigger a browser crash.
What type of attack does CVE-2005-4840 facilitate?
CVE-2005-4840 facilitates a denial of service attack through a NULL dereference in the OutlookExpress.AddressBook COM object.