5

CVE-2006-3354

Exploit

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftIe Version6 Editionwindows_xp_professional_64bit
MicrosoftIe Version6 Updatesp1 Editionwindows_98
MicrosoftIe Version6 Updatesp1 Editionwindows_98_se
MicrosoftIe Version6 Updatesp1 Editionwindows_millennium
MicrosoftIe Version6 Updatesp1 Editionwindows_xpsp1
MicrosoftIe Version6 Updatewindows_2000_sp4
MicrosoftIe Version6 Updatewindows_server_2003_sp1
MicrosoftIe Version6 Updatewindows_server_2003_sp1_itanium
MicrosoftIe Version6 Updatewindows_server_2003_sp1_itanium_systems
MicrosoftIe Version6 Updatewindows_xp_sp2
MicrosoftIe Version6.0 Editionwindows_server_2003
MicrosoftIe Version6.0 Updatesp1
MicrosoftIe Version6.0 Updatesp2
MicrosoftIe Version6.0 Updatewindows_xp_sp2
MicrosoftInternet Explorer Version6 Updatesp1
MicrosoftInternet Explorer Version6.0
MicrosoftInternet Explorer Version6.0.2600
MicrosoftInternet Explorer Version6.0.2800
MicrosoftInternet Explorer Version6.0.2800.1106
MicrosoftInternet Explorer Version6.0.2900.2180
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 41.07% 0.971
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P