First published: Fri Mar 17 2006(Updated: )
Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1245 is considered a critical vulnerability due to its potential for remote code execution.
To remediate CVE-2006-1245, users should update to a newer, patched version of Microsoft Internet Explorer.
Exploiting CVE-2006-1245 could allow an attacker to execute arbitrary code on the affected system, potentially leading to data compromise or system loss.
CVE-2006-1245 primarily affects Microsoft Internet Explorer 6.0.2900.2180 and possibly other versions prior to the security update.
Yes, CVE-2006-1245 can be exploited via a malicious web page containing specially crafted HTML tags with script action handlers.