CVE-2006-1359

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
References
Link Resource
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1427.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1430.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1434.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1662.html
http://secunia.com/advisories/18680 Vendor Advisory
http://secunia.com/secunia_research/2006-7/advisory/
http://securitytracker.com/id?1015812
http://www.ciac.org/ciac/bulletins/q-154.shtml
http://www.computerterrorism.com/research/ct22-03-2006 Vendor Advisory
http://www.kb.cert.org/vuls/id/876678 US Government Resource
http://www.microsoft.com/technet/security/advisory/917077.mspx
http://www.osvdb.org/24050
http://www.securityfocus.com/archive/1/428441
http://www.securityfocus.com/archive/1/428583/100/0/threaded
http://www.securityfocus.com/archive/1/428600/100/0/threaded
http://www.securityfocus.com/archive/1/429088/100/0/threaded
http://www.securityfocus.com/archive/1/429124/30/6120/threaded
http://www.securityfocus.com/bid/17196 Exploit
http://www.us-cert.gov/cas/techalerts/TA06-101A.html US Government Resource
http://www.vupen.com/english/advisories/2006/1050
http://www.vupen.com/english/advisories/2006/1318
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-013
https://exchange.xforce.ibmcloud.com/vulnerabilities/25379
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1178
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1657
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1678
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1702
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A985
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1427.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1430.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1434.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1662.html
http://secunia.com/advisories/18680 Vendor Advisory
http://secunia.com/secunia_research/2006-7/advisory/
http://securitytracker.com/id?1015812
http://www.ciac.org/ciac/bulletins/q-154.shtml
http://www.computerterrorism.com/research/ct22-03-2006 Vendor Advisory
http://www.kb.cert.org/vuls/id/876678 US Government Resource
http://www.microsoft.com/technet/security/advisory/917077.mspx
http://www.osvdb.org/24050
http://www.securityfocus.com/archive/1/428441
http://www.securityfocus.com/archive/1/428583/100/0/threaded
http://www.securityfocus.com/archive/1/428600/100/0/threaded
http://www.securityfocus.com/archive/1/429088/100/0/threaded
http://www.securityfocus.com/archive/1/429124/30/6120/threaded
http://www.securityfocus.com/bid/17196 Exploit
http://www.us-cert.gov/cas/techalerts/TA06-101A.html US Government Resource
http://www.vupen.com/english/advisories/2006/1050
http://www.vupen.com/english/advisories/2006/1318
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-013
https://exchange.xforce.ibmcloud.com/vulnerabilities/25379
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1178
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1657
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1678
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1702
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A985
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:7.0:beta_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:08

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1427.html - () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1427.html -
References () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1430.html - () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1430.html -
References () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1434.html - () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1434.html -
References () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1662.html - () http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1662.html -
References () http://secunia.com/advisories/18680 - Vendor Advisory () http://secunia.com/advisories/18680 - Vendor Advisory
References () http://secunia.com/secunia_research/2006-7/advisory/ - () http://secunia.com/secunia_research/2006-7/advisory/ -
References () http://securitytracker.com/id?1015812 - () http://securitytracker.com/id?1015812 -
References () http://www.ciac.org/ciac/bulletins/q-154.shtml - () http://www.ciac.org/ciac/bulletins/q-154.shtml -
References () http://www.computerterrorism.com/research/ct22-03-2006 - Vendor Advisory () http://www.computerterrorism.com/research/ct22-03-2006 - Vendor Advisory
References () http://www.kb.cert.org/vuls/id/876678 - US Government Resource () http://www.kb.cert.org/vuls/id/876678 - US Government Resource
References () http://www.microsoft.com/technet/security/advisory/917077.mspx - () http://www.microsoft.com/technet/security/advisory/917077.mspx -
References () http://www.osvdb.org/24050 - () http://www.osvdb.org/24050 -
References () http://www.securityfocus.com/archive/1/428441 - () http://www.securityfocus.com/archive/1/428441 -
References () http://www.securityfocus.com/archive/1/428583/100/0/threaded - () http://www.securityfocus.com/archive/1/428583/100/0/threaded -
References () http://www.securityfocus.com/archive/1/428600/100/0/threaded - () http://www.securityfocus.com/archive/1/428600/100/0/threaded -
References () http://www.securityfocus.com/archive/1/429088/100/0/threaded - () http://www.securityfocus.com/archive/1/429088/100/0/threaded -
References () http://www.securityfocus.com/archive/1/429124/30/6120/threaded - () http://www.securityfocus.com/archive/1/429124/30/6120/threaded -
References () http://www.securityfocus.com/bid/17196 - Exploit () http://www.securityfocus.com/bid/17196 - Exploit
References () http://www.us-cert.gov/cas/techalerts/TA06-101A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-101A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/1050 - () http://www.vupen.com/english/advisories/2006/1050 -
References () http://www.vupen.com/english/advisories/2006/1318 - () http://www.vupen.com/english/advisories/2006/1318 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-013 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-013 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25379 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25379 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1178 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1178 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1657 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1657 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1678 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1678 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1702 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1702 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A985 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A985 -

Information

Published : 2006-03-23 00:06

Updated : 2025-04-03 01:03


NVD link : CVE-2006-1359

Mitre link : CVE-2006-1359

CVE.ORG link : CVE-2006-1359


JSON object : View

Products Affected

microsoft

  • ie
  • internet_explorer
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')