Vulnerability Description
Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size than the INPUT.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Ie | <= 6 |
References
- http://archives.neohapsis.com/archives/bugtraq/2006-07/0199.html
- http://jonas.elunic.de/blog/index.php/2006/07/14/ie-freeze-bug/
- http://www.osvdb.org/28614
- http://archives.neohapsis.com/archives/bugtraq/2006-07/0199.html
- http://jonas.elunic.de/blog/index.php/2006/07/14/ie-freeze-bug/
- http://www.osvdb.org/28614
FAQ
What is CVE-2006-4888?
CVE-2006-4888 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size tha...
How severe is CVE-2006-4888?
CVE-2006-4888 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4888?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Ie.