- Servers
- Desktops
- Laptops
- Tablet PCs
- PDAs
- Smart phones
- Digital cameras
- Camcorders
- Printers & multifunction devices
- Scanners
- Copiers
- Monitors & projectors
- Hard drives & burners
- Peripherals
- Productivity
- Accounting & finance
- Data management
- Graphics & publishing
- Web publishing
- Operating systems
- Security & utilities
- Downloads & trial software
- Handheld software
- Instant messaging
- Cell phones & plans
- Voice over Internet
- Telephones
- Routers & gateways
- Wireless networking
- Network adapters
- Internet access
- Web hosting
- Domain search
- Hotspot Zone
- Desktops
- Laptops
- Servers and storage
- PDAs
- Cell phones
- Monitors & projectors
- Printers
- Networking and wireless
- Security and utility software
- Productivity software
- Access, hosting, and services
- All business buying guides
CNET Security Center: Your complete source of antivirus and Internet security information.
Internet Explorer "FolderItem" Object Access Remote Denial of Service Vulnerability
Flaw may crash Internet Explorer with specially crafted Web pages.
By Robert Vamosi (July 25, 2006)
This vulnerability may cause a denial of service (crash) within Microsoft Internet Explorer 6. By accessing the object references of a FolderItem ActiveX object--specifcally, by creating a NULL pointer dereference error when accessing a "FolderItem" object--attackers may crash the Microsoft browser. Successful execution, however, requires a victim to access a malicious Web page.
Flaw may crash Internet Explorer with specially crafted Web pages.
By Robert Vamosi (July 25, 2006)
QUICK FACTS
Name: Internet Explorer "FolderItem" Object Access Remote Denial of Service Vulnerability
Date first reported: 07/18/06
Software vulnerable: Internet Explorer 5.01 through 6
What it does: Causes a denial of service (crash).
Recommendations: None at this time
Exploit code available: No
Vendor patch available: No
Date first reported: 07/18/06
Software vulnerable: Internet Explorer 5.01 through 6
What it does: Causes a denial of service (crash).
Recommendations: None at this time
Exploit code available: No
Vendor patch available: No
Additional Resources:
- French Security Incident Response Team: ADV-2006-2814
- BrowserFun: #15
- NIST: CVE-2006-3658
