CVE-2006-6310: Medium severity microsoft internet explorer vulnerability
Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6310?
CVE-2006-6310 has been identified as a denial of service vulnerability.
How does CVE-2006-6310 affect Internet Explorer?
CVE-2006-6310 allows remote attackers to crash Internet Explorer by using an invalid src attribute value in an HTML frame tag.
What versions of Internet Explorer are affected by CVE-2006-6310?
CVE-2006-6310 affects Microsoft Internet Explorer 6.0 SP1 and earlier versions.
Is CVE-2006-6310 easily exploitable?
Yes, CVE-2006-6310 can be exploited by simply causing an invalid src attribute value to be processed by the browser.
What mitigation techniques exist for CVE-2006-6310?
Updating to a newer version of Internet Explorer that is not affected by CVE-2006-6310 is the best mitigation approach.