First published: Mon Nov 16 2009(Updated: )
Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | >=6<=6.0.2900.2180 | |
Internet Explorer | >=7.0<=7.0.6000.16711 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3943 is classified as a denial of service vulnerability.
CVE-2009-3943 allows remote attackers to hang the application through a JavaScript loop.
CVE-2009-3943 affects Internet Explorer versions 6 and 7.
The exploit in CVE-2009-3943 relies on configuring the home page using the setHomePage method.
To protect against CVE-2009-3943, consider upgrading to a newer version of Internet Explorer.