peter bassill · operator
$ cve CVE-2006-1190 JSON

CVE-2006-1190 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 61.3% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS61.29% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2006-04-11
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD