First published: Thu Oct 02 2008(Updated: )
Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5 | |
Internet Explorer | =7 | |
Internet Explorer | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4381 has a moderate severity level as it allows remote attackers to cause a denial of service through application crashes.
CVE-2008-4381 affects Microsoft Internet Explorer versions 5, 6, and 7.
To mitigate CVE-2008-4381, users should upgrade to a more recent version of Internet Explorer or apply relevant security patches.
CVE-2008-4381 is associated with denial of service attacks that can crash Internet Explorer.
A temporary workaround for CVE-2008-4381 is to avoid executing JavaScript that could trigger the alert function with invalid characters.