{"api_version":"1","generated_at":"2026-07-23T08:13:16+00:00","cve":"CVE-2006-3450","urls":{"html":"https://cve.report/CVE-2006-3450","api":"https://cve.report/api/cve/CVE-2006-3450.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3450","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3450"},"summary":{"title":"CVE-2006-3450","description":"Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file.","state":"PUBLIC","assigner":"secure@microsoft.com","published_at":"2006-08-08 23:04:00","updated_at":"2021-07-23 12:55:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/archive/1/442579/100/0/threaded","name":"20060808 ZDI-06-027: Microsoft Internet Explorer CSS Class Ordering Memory Corruption Vulnerability","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/119180","name":"VU#119180","refsource":"CERT-VN","tags":["Patch","US Government Resource"],"title":"US-CERT Vulnerability Note VU#119180","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21396","name":"21396","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Internet Explorer Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042","name":"MS06-042","refsource":"MS","tags":[],"title":"Microsoft Security Bulletin MS06-042 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3212","name":"ADV-2006-3212","refsource":"VUPEN","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-06-027.html","name":"http://www.zerodayinitiative.com/advisories/ZDI-06-027.html","refsource":"MISC","tags":[],"title":"ZDI-06-027","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19312","name":"19312","refsource":"BID","tags":["Patch"],"title":"Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA06-220A.html","name":"TA06-220A","refsource":"CERT","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA06-220A -- Microsoft Products Contain Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A433","name":"oval:org.mitre.oval:def:433","refsource":"OVAL","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016663","name":"1016663","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Microsoft Internet Explorer Bugs Let Remote Users Obtain Information or Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27855","name":"27855","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3450","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3450","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3450","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3450","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3450","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3450","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3450","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2006-3450","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"oval:org.mitre.oval:def:433","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A433"},{"name":"1016663","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016663"},{"name":"MS06-042","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042"},{"name":"27855","refsource":"OSVDB","url":"http://www.osvdb.org/27855"},{"name":"VU#119180","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/119180"},{"name":"21396","refsource":"SECUNIA","url":"http://secunia.com/advisories/21396"},{"name":"ADV-2006-3212","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3212"},{"name":"20060808 ZDI-06-027: Microsoft Internet Explorer CSS Class Ordering Memory Corruption Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/442579/100/0/threaded"},{"name":"19312","refsource":"BID","url":"http://www.securityfocus.com/bid/19312"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-06-027.html","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-06-027.html"},{"name":"TA06-220A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA06-220A.html"}]}},"nvd":{"publishedDate":"2006-08-08 23:04:00","lastModifiedDate":"2021-07-23 12:55:00","problem_types":["CWE-20"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3450","Ordinal":"18775","Title":"CVE-2006-3450","CVE":"CVE-2006-3450","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3450","Ordinal":"1","NoteData":"Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3450","Ordinal":"2","NoteData":"2006-08-08","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3450","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}