Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News July 2, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:3137 Date: 2007-01-13
Title: IE6 DHTML Method Heap Memory Corruption Vulnerability (Server 2003)
Description: Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."
Version: 3 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-0055
Family: windows
Platform(s): Microsoft Windows Server 2003 Product(s): Microsoft Internet Explorer
Definition Synopsis:

OVAL is CVE Compatible