CVE-2006-3357
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 35%
exploitation probability
35%top 2% of all CVEs
observed exploitation
nono source reports it
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
Affected products
n/a · n/aReferences
http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046http://secunia.com/advisories/20906http://securitytracker.com/id?1016434https://exchange.xforce.ibmcloud.com/vulnerabilities/27573https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13http://www.kb.cert.org/vuls/id/159220http://www.osvdb.org/26835http://www.securityfocus.com/archive/1/442733/100/0/threadedhttp://www.securityfocus.com/bid/18769http://www.tippingpoint.com/security/advisories/TSRT-06-08.htmlhttp://www.us-cert.gov/cas/techalerts/TA06-220A.html