CVE-2006-7065
medium · 5Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
5
CVSS
19.9%
EPSS (exploit prob.)
97th
EPSS percentile
2007-03-02
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 6.0 |
| microsoft | ie | 7 |
| microsoft | ie | 7 |
| microsoft | ie | 7 |
| microsoft | ie | 7 |
| microsoft | ie | 7.0 |
| microsoft | ie | 7.0 |
| microsoft | ie | 7.0 |
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 6.0 |
| microsoft | internet_explorer | 6.0.2600 |
| microsoft | internet_explorer | 6.0.2800 |
| microsoft | internet_explorer | 6.0.2800.1106 |
| microsoft | internet_explorer | 6.0.2900 |
| microsoft | internet_explorer | 6.0.2900.2180 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0163.html
- http://www.securityfocus.com/bid/19364
- http://www3.ca.com/be/securityadvisor/vulninfo/Vuln.aspx?ID=34511
- http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0163.html
- http://www.securityfocus.com/bid/19364
- http://www3.ca.com/be/securityadvisor/vulninfo/Vuln.aspx?ID=34511
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-7065