CVE-2006-3357
Summary
| CVE | CVE-2006-3357 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-06 20:05:00 UTC |
| Updated | 2021-07-23 12:55:00 UTC |
| Description | Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Microsoft HTML Help Heap Overflow in HHCtrl ActiveX Control May Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Microsoft Windows HTML Help HHCtrl ActiveX Control Memory Corruption Vulnerability | BID | www.securityfocus.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Windows HTML Help ActiveX Control Memory Corruption - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Browser Fun: MoBB #2: Internet.HHCtrl Image Property | MISC | browserfun.blogspot.com | |
| US-CERT Vulnerability Note VU#159220 | CERT-VN | www.kb.cert.org | US Government Resource |
| Microsoft Security Bulletin MS06-046 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| US-CERT Technical Cyber Security Alert TA06-220A -- Microsoft Products Contain Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| 26835 | OSVDB | www.osvdb.org | |
| Intrusion Prevention IPS | TippingPoint, a division of 3Com | Published Advisories | MISC | www.tippingpoint.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.