Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1190
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1190

Description:
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25552

ST
  1015900

SAID
  Secunia Advisory: SA18957

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1735
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1541
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1783
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:965

MS
  http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx

CERT-VN
  959649

BID
  17455


Return to the previous page.