Vulnerabilities > CVE-2006-3899 - Unspecified vulnerability in Microsoft Internet Explorer 6.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid memory access inside the SysAllocStringLen function.

Vulnerable Configurations

Part Description Count
Application
Microsoft
3
OS
Microsoft
1

Exploit-Db

descriptionMicrosoft Internet Explorer 6.0 String To Binary Function Denial Of Service Vulnerability. CVE-2006-3899 . Dos exploit for windows platform
idEDB-ID:28252
last seen2016-02-03
modified2006-07-20
published2006-07-20
reporterhdm
sourcehttps://www.exploit-db.com/download/28252/
titleMicrosoft Internet Explorer 6.0 String To Binary Function Denial of Service Vulnerability