5

CVE-2009-2954

Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftInternet Explorer Version <= 6.0.2900.2180
MicrosoftInternet Explorer Version3.0
MicrosoftInternet Explorer Version3.0.1
MicrosoftInternet Explorer Version3.0.2
MicrosoftInternet Explorer Version3.1
MicrosoftInternet Explorer Version3.2
MicrosoftInternet Explorer Version4.0
MicrosoftInternet Explorer Version4.0.1
MicrosoftInternet Explorer Version4.0.1 Updatesp1
MicrosoftInternet Explorer Version4.0.1 Updatesp2
MicrosoftInternet Explorer Version4.01
MicrosoftInternet Explorer Version4.1
MicrosoftInternet Explorer Version4.01 Updatesp1
MicrosoftInternet Explorer Version4.5
MicrosoftInternet Explorer Version4.40.308
MicrosoftInternet Explorer Version4.40.520
MicrosoftInternet Explorer Version4.70.1155
MicrosoftInternet Explorer Version4.70.1158
MicrosoftInternet Explorer Version4.70.1215
MicrosoftInternet Explorer Version4.70.1300
MicrosoftInternet Explorer Version4.71.544
MicrosoftInternet Explorer Version4.71.1008.3
MicrosoftInternet Explorer Version4.71.1712.6
MicrosoftInternet Explorer Version4.72.2106.8
MicrosoftInternet Explorer Version4.72.3110.8
MicrosoftInternet Explorer Version4.72.3612.1713
MicrosoftInternet Explorer Version5.0
MicrosoftInternet Explorer Version5.0.1
MicrosoftInternet Explorer Version5.0.1 Updatesp1
MicrosoftInternet Explorer Version5.0.1 Updatesp2
MicrosoftInternet Explorer Version5.0.1 Updatesp3
MicrosoftInternet Explorer Version5.0.1 Updatesp4
MicrosoftInternet Explorer Version5.00.0518.10
MicrosoftInternet Explorer Version5.00.0910.1309
MicrosoftInternet Explorer Version5.00.2014.0216
MicrosoftInternet Explorer Version5.00.2314.1003
MicrosoftInternet Explorer Version5.00.2516.1900
MicrosoftInternet Explorer Version5.00.2614.3500
MicrosoftInternet Explorer Version5.00.2919.800
MicrosoftInternet Explorer Version5.00.2919.3800
MicrosoftInternet Explorer Version5.00.2919.6307
MicrosoftInternet Explorer Version5.00.2920.0000
MicrosoftInternet Explorer Version5.00.3103.1000
MicrosoftInternet Explorer Version5.00.3105.0106
MicrosoftInternet Explorer Version5.00.3314.2101
MicrosoftInternet Explorer Version5.00.3315.1000
MicrosoftInternet Explorer Version5.00.3502.1000
MicrosoftInternet Explorer Version5.00.3700.1000
MicrosoftInternet Explorer Version5.01
MicrosoftInternet Explorer Version5.1
MicrosoftInternet Explorer Version5.01 Updatesp1
MicrosoftInternet Explorer Version5.01 Updatesp2
MicrosoftInternet Explorer Version5.01 Updatesp3
MicrosoftInternet Explorer Version5.01 Updatesp4
MicrosoftInternet Explorer Version5.2.3
MicrosoftInternet Explorer Version5.5
MicrosoftInternet Explorer Version5.5 Updatepreview
MicrosoftInternet Explorer Version5.5 Updatesp1
MicrosoftInternet Explorer Version5.5 Updatesp2
MicrosoftInternet Explorer Version5.50.3825.1300
MicrosoftInternet Explorer Version5.50.4030.2400
MicrosoftInternet Explorer Version5.50.4134.0100
MicrosoftInternet Explorer Version5.50.4134.0600
MicrosoftInternet Explorer Version5.50.4308.2900
MicrosoftInternet Explorer Version5.50.4522.1800
MicrosoftInternet Explorer Version5.50.4807.2300
MicrosoftInternet Explorer Version6.0
MicrosoftInternet Explorer Version6.00.2462.0000
MicrosoftInternet Explorer Version6.00.2479.0006
MicrosoftInternet Explorer Version6.0.2600
MicrosoftInternet Explorer Version6.00.2600.0000
MicrosoftInternet Explorer Version6.0.2800
MicrosoftInternet Explorer Version6.0.2800.1106
MicrosoftInternet Explorer Version6.0.2900
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 13.65% 0.936
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.