Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1303
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1303

Description:
Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/26774

ST
  1016291

SAID
  Secunia Advisory: SA20595

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1928
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1830
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1767
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1135
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1973
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2017

OSVDB
  26442

MS
  http://www.microsoft.com/technet/security/bulletin/ms06-021.mspx

MISC
  http://www.zerodayinitiative.com/advisories/ZDI-06-018.html

CERT-VN
  959049

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/437041/100/0/threaded

BID
  18328


Return to the previous page.