9.3
CVSSv2

CVE-2006-2383

Published: 13/06/2006 Updated: 23/07/2021
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and previous versions allows remote malicious users to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 5.01

microsoft internet explorer 6

Exploits

source: wwwsecurityfocuscom/bid/18303/info The DXImageTransformMicrosoftLight ActiveX control is prone to remote code execution An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page <!-- MS Internet Explorer 6 DirectX Media DoS Vulnerability DLL: dxtmsftdll Discovered &am ...