CVE-2006-1992: Low severity Microsoft Internet Explorer vulnerability
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1992?
CVE-2006-1992 is classified as a denial of service vulnerability.
How do I fix CVE-2006-1992?
To address CVE-2006-1992, users should upgrade to a more recent version of Microsoft Internet Explorer.
What versions of Internet Explorer are affected by CVE-2006-1992?
CVE-2006-1992 affects Microsoft Internet Explorer version 6.0.2900.
Can CVE-2006-1992 allow for code execution?
CVE-2006-1992 was initially theorized to allow code execution, but it primarily causes denial of service.
What type of attack does CVE-2006-1992 exploit?
CVE-2006-1992 can be exploited through nested OBJECT tags to trigger invalid pointer dereferences.