Vulnerabilities > CVE-2006-7206 - Unspecified vulnerability in Microsoft Internet Explorer 6

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
microsoft
exploit available

Summary

Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.

Vulnerable Configurations

Part Description Count
OS
Microsoft
1
Application
Microsoft
1

Exploit-Db

descriptionMS Internet Explorer Recordset Double Free Memory Exploit (MS07-009). CVE-2006-7206. Remote exploit for windows platform
idEDB-ID:3577
last seen2016-01-31
modified2007-03-26
published2007-03-26
reporterN/A
sourcehttps://www.exploit-db.com/download/3577/
titleMicrosoft Internet Explorer - Recordset Double Free Memory Exploit MS07-009