Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News December 4, 2008 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:1294 Date: 2007-01-22
Title: IFRAME Vulnerability
Description: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
Version: 5 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2004-1050
Family: windows
Platform(s): Microsoft Windows 98
Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:

OVAL is CVE Compatible