peter bassill · operator
$ cve CVE-2006-4301 JSON

CVE-2006-4301 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 39.1% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1) DXImageTransform.Microsoft.MaskFilter.1, (2) DXImageTransform.Microsoft.Chroma.1, and (3) DX3DTransform.Microsoft.Shapes.1.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS39.05% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2006-08-23
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftie

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD