First published: Tue Feb 21 2006(Updated: )
The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location" variable within the loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6.0.2900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0830 has been categorized as a medium severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2006-0830, users should update to a version of Internet Explorer that is no longer vulnerable or apply any available security patches from Microsoft.
CVE-2006-0830 specifically affects Internet Explorer version 6.0.2900.
Yes, CVE-2006-0830 can be exploited remotely through specially crafted web pages containing infinite loops in JavaScript or VBScript.
CVE-2006-0830 can lead to denial of service attacks and potentially allow attackers to execute arbitrary code.