MEDIUM · 5.0

CVE-2006-7030

Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required argument...

Vulnerability Description

Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftWindows 2000All versions
MicrosoftWindows 2003 Serversp2
MicrosoftWindows 98All versions
MicrosoftWindows MeAll versions
MicrosoftWindows NtAll versions
MicrosoftWindows VistaAll versions
MicrosoftWindows XpAll versions
MicrosoftIe6.0

References

FAQ

What is CVE-2006-7030?

CVE-2006-7030 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required argument...

How severe is CVE-2006-7030?

CVE-2006-7030 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-7030?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2000, Microsoft Windows 2003 Server, Microsoft Windows 98, Microsoft Windows Me, Microsoft Windows Nt.