CVE-2006-3471: Medium severity Microsoft ie vulnerability
Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3471?
CVE-2006-3471 has been classified as a denial of service vulnerability that can cause Microsoft Internet Explorer 6 to crash.
Which versions of Microsoft Internet Explorer are affected by CVE-2006-3471?
CVE-2006-3471 affects Microsoft Internet Explorer 6.0 and 6.0 SP1 running on Windows XP.
How do I fix CVE-2006-3471?
To fix CVE-2006-3471, users should upgrade to a more recent version of Internet Explorer or apply relevant security patches provided by Microsoft.
What type of attack does CVE-2006-3471 facilitate?
CVE-2006-3471 allows remote attackers to execute a denial of service attack that crashes the browser.
Is CVE-2006-3471 still a threat today?
While older versions of Internet Explorer may still be vulnerable, the threat is significantly reduced for users who have updated their browsers.