First published: Mon Jul 31 2006(Updated: )
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6-windows_xp_sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3944 has a severity rating that indicates it can cause a denial of service in Microsoft Internet Explorer 6.
To fix CVE-2006-3944, users should apply the latest updates and patches provided by Microsoft for Internet Explorer 6.
CVE-2006-3944 affects users of Microsoft Internet Explorer 6 running on Windows XP SP2.
CVE-2006-3944 can lead to application crashes due to integer overflow exceptions caused by manipulated Forms.ListBox.1 objects.
Yes, CVE-2006-3944 can be exploited remotely by attackers to cause a denial of service.