 |
|
|
|
Multiple Microsoft Internet Explorer security vulnerabilities updated since 22.03.2006 | | Published: |  | 27.05.2006 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 5923 | | Type: |  | client | | Level: |  | 9/10 | | Description: |  | Jump to ininitialized function pointer by referencing unspupported object's method (createTextRange() for checkbox). Potentially can be used for code execution and hidden malware installation. Memory corruption on uninitialized event handlers. HTA code execution. HTML parsing memory corrution. COM objects memory corruption. Crossite scripting. |
| Original document |  | Thomas Waldegger, [BuHa-Security] DoS Vulnerability in MS IE 6 SP2 (27.05.2006) |
| |  | Thomas Waldegger, [BuHa-Security] MS06-013: HTML Tag Memory Corruption Vulnerability in MS IE 6 SP2 (27.05.2006) |
| |  | Thomas Waldegger, [BuHa-Security] Multiple Vulnerabilities in MS IE 6.0 SP2 (13.04.2006) |
| |  | Sowhat ., [Full-disclosure] Microsoft Internet Explorer DBCS Remote Memory Corruption Vulnerability (12.04.2006) |
| |  | X-FORCE, ISS Protection Bried: ie_patch_ms_06-13 (12.04.2006) |
| |  | Sowhat ., Microsoft Internet Explorer DBCS Remote Memory Corruption Vulnerability (12.04.2006) |
| |  | CERT, US-CERT Technical Cyber Security Alert TA06-101A -- Microsoft Windows and Internet Explorer Vulnerabilities (12.04.2006) |
| |  | MICROSOFT, Microsoft Security Bulletin MS06-013 Cumulative Security Update for Internet Explorer (912812) (11.04.2006) |
| |  | Determina Secure, Determina Fix for CVE-2006-1359 (Zero Day MS Internet Explorer Remote "CreateTextRange()" Code Execution) (29.03.2006) |
| |  | EEYE, [Full-disclosure] EEYE: Temporary workaround for IE createTextRange vulnerability (28.03.2006) |
| |  | H D Moore, [Full-disclosure] Fun with DHTML (23.03.2006) |
| |  | SECUNIA, [SA18680] Microsoft Internet Explorer "createTextRange()" Code Execution (22.03.2006) |
| |  | Computer Terrorism (UK) :: Incident Response Centre, [Full-disclosure] Microsoft Internet Explorer (mshtml.dll) - Remote Code Execution (22.03.2006) |
| |  | Stelian Ene, [Full-disclosure] IE crash (22.03.2006) |
|
|
|
|
|
|
|
|