CVE-2006-7065: Null Pointer Dereference
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7065?
CVE-2006-7065 is classified as a denial of service vulnerability that can crash the affected versions of Microsoft Internet Explorer.
How does CVE-2006-7065 exploit Microsoft Internet Explorer?
CVE-2006-7065 exploits Microsoft Internet Explorer by causing a crash through a malicious IFRAME containing specific XML and XSL files.
Which versions of Microsoft Internet Explorer are affected by CVE-2006-7065?
CVE-2006-7065 affects Microsoft Internet Explorer versions 6 and 7 running on Windows XP and Windows 2000.
How do I fix CVE-2006-7065?
To mitigate CVE-2006-7065, users should update to the latest security patches provided by Microsoft for Internet Explorer.
What are the impacts of CVE-2006-7065?
The primary impact of CVE-2006-7065 is the denial of service that results in a crash of the browser, potentially disrupting user activity.