First published: Wed Dec 06 2006(Updated: )
Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | <=6.0 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6310 has been identified as a denial of service vulnerability.
CVE-2006-6310 allows remote attackers to crash Internet Explorer by using an invalid src attribute value in an HTML frame tag.
CVE-2006-6310 affects Microsoft Internet Explorer 6.0 SP1 and earlier versions.
Yes, CVE-2006-6310 can be exploited by simply causing an invalid src attribute value to be processed by the browser.
Updating to a newer version of Internet Explorer that is not affected by CVE-2006-6310 is the best mitigation approach.