First published: Thu Jul 06 2006(Updated: )
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-windows_xp_sp2 | |
Microsoft Internet Explorer | =6-windows_2000_sp4 | |
Canon Network Camera Server VB101 | ||
Microsoft Internet Explorer | =6-windows_server_2003_sp1_itanium_systems | |
Microsoft Internet Explorer | =6.0-sp1 | |
Internet Explorer | =6-sp1 | |
Microsoft Internet Explorer | =6 | |
Microsoft Internet Explorer | =6-sp1 | |
Microsoft Internet Explorer | =6-sp1 | |
Microsoft Internet Explorer | =6.0-sp2 | |
Microsoft Internet Explorer | =6-windows_server_2003_sp1 | |
Microsoft Internet Explorer | =6-windows_server_2003_sp1_itanium | |
Microsoft Internet Explorer | =6.0 | |
Microsoft Internet Explorer | =6-sp1 | |
Microsoft Internet Explorer | =6-sp1 | |
Microsoft Internet Explorer | =6-windows_xp_sp2 | |
Internet Explorer | =6.0.2600 | |
Internet Explorer | =6.0 | |
Internet Explorer | =6.0.2800 | |
Internet Explorer | =6.0.2800.1106 | |
Internet Explorer | =6.0.2900.2180 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3354 has been identified as a denial of service vulnerability.
To mitigate CVE-2006-3354, update to a newer version of Microsoft Internet Explorer that does not allow this vulnerability.
CVE-2006-3354 affects multiple versions, including Microsoft Internet Explorer 6 on Windows XP, Windows 2000, and Windows Server 2003.
CVE-2006-3354 can be exploited by remote attackers to crash the Internet Explorer application.
CVE-2006-3354 is primarily a risk for legacy systems still running unsupported versions of Internet Explorer 6.