First published: Tue Jun 01 2010(Updated: )
Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =8.0.7600.16385 | |
Internet Explorer | =6.0.2900.2180 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2118 has a severity rating of medium, as it allows for denial of service through resource consumption.
To mitigate CVE-2010-2118, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
CVE-2010-2118 affects Internet Explorer 6.0.2900.2180 and 8.0.7600.16385.
CVE-2010-2118 facilitates a denial of service attack via JavaScript code that generates infinite loops creating IFRAME elements.
Yes, CVE-2010-2118 can be exploited remotely by attackers using specially crafted JavaScript.