5
CVSSv2

CVE-2004-2434

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Microsoft Internet Explorer 6.0 SP1 allows remote malicious users to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft ie 6.0

Exploits

<center><a href=::%7b>Right Click aOn Me And Click "Save Target As"</a> // milw0rmcom [2004-08-04] ...