Vulnerabilities > CVE-2006-3357 - Unspecified vulnerability in Microsoft Internet Explorer 6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-046.NASL |
description | The remote host contains a version of the HTML Help ActiveX control that could allow an attacker to execute arbitrary code on the remote host by constructing a malicious web page and entice a victim to visit this web page. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22188 |
published | 2006-08-08 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22188 |
title | MS06-046: Vulnerability in HTML Help Could Allow Remote Code Execution (922616) |
code |
|
Oval
accepted | 2011-05-09T04:01:09.767-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:13 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2006-08-11T12:53:40 | ||||||||||||||||||||||||
title | Buffer Overrun in HTML Help Vulnerability | ||||||||||||||||||||||||
version | 71 |
References
- http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html
- http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html
- http://secunia.com/advisories/20906
- http://secunia.com/advisories/20906
- http://securitytracker.com/id?1016434
- http://securitytracker.com/id?1016434
- http://www.kb.cert.org/vuls/id/159220
- http://www.kb.cert.org/vuls/id/159220
- http://www.osvdb.org/26835
- http://www.osvdb.org/26835
- http://www.securityfocus.com/archive/1/442733/100/0/threaded
- http://www.securityfocus.com/archive/1/442733/100/0/threaded
- http://www.securityfocus.com/bid/18769
- http://www.securityfocus.com/bid/18769
- http://www.tippingpoint.com/security/advisories/TSRT-06-08.html
- http://www.tippingpoint.com/security/advisories/TSRT-06-08.html
- http://www.us-cert.gov/cas/techalerts/TA06-220A.html
- http://www.us-cert.gov/cas/techalerts/TA06-220A.html
- http://www.vupen.com/english/advisories/2006/2634
- http://www.vupen.com/english/advisories/2006/2634
- http://www.vupen.com/english/advisories/2006/2635
- http://www.vupen.com/english/advisories/2006/2635
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27573
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27573
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13