Description
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
Affected products
- microsoft / internet_explorer4.0 – 4.0
- microsoft / Outlook2000 – 2000
- microsoft / outlook_express5.5 – 5.5
Exploits & proofs of concept
- exploit-dbMicrosoft Internet Explorer 4 / Outlook 2000/5.5 - 'MSHTML.dll' Crashby Thor Larholm
Updated 5m ago · 8 sources