CVE-2010-1991: Medium severity Microsoft ie vulnerability
Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1991?
CVE-2010-1991 is considered a denial of service vulnerability affecting specific versions of Microsoft Internet Explorer.
How does CVE-2010-1991 exploit work?
CVE-2010-1991 exploits the IFRAME element with a mailto: URL, causing excessive application launches when rendered in the browser.
What versions of Internet Explorer are affected by CVE-2010-1991?
CVE-2010-1991 affects Microsoft Internet Explorer versions 6, 7, and 8.0.7600.16385.
How do I mitigate CVE-2010-1991?
To mitigate CVE-2010-1991, consider upgrading to a more recent version of Internet Explorer or apply security patches provided by Microsoft.
Is there a workaround for CVE-2010-1991?
A potential workaround for CVE-2010-1991 is to disable the use of scripts and IFRAME elements in untrusted web content.