First published: Wed Aug 30 2006(Updated: )
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4446 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-4446, users should apply the latest security updates provided by Microsoft for Internet Explorer.
CVE-2006-4446 affects Microsoft Internet Explorer version 6.0 SP1.
CVE-2006-4446 facilitates a denial of service attack and may allow attackers to execute arbitrary code.
While specific workarounds are limited, avoiding the use of vulnerable features in Internet Explorer may help mitigate the risk.