AplusWebMaster
Topic Starter
FYI…(MS updates per US-CERT)
"Summary of Security Items from April 20 through April 26, 2006
- http://www.us-cert.gov/cas/bulletins/SB06-117.html#win1
> Microsoft Outlook Express
- http://www.microsoft.com/technet/security/…n/ms06-016.mspx
V1.2: Revised due to issues discovered with the security update…
> Microsoft Windows Explorer
- http://www.microsoft.com/technet/security/…n/ms06-015.mspx
V2.0: Revised to inform customers that revised versions of the security update are available.
> Microsoft Internet Explorer 6.0 SP2
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-1992
Last revised: 4/26/2006
Source: US-CERT/NIST
Overview
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via nested OBJECT tags, which trigger invalid pointer dererences including NULL dereferences.
Impact
CVSS Severity: 8.0 (High)
Range: Remotely exploitable
Authentication: Not required to exploit
Impact Type: Provides user account access, Allows disruption of service…"

"Summary of Security Items from April 20 through April 26, 2006
- http://www.us-cert.gov/cas/bulletins/SB06-117.html#win1
> Microsoft Outlook Express
- http://www.microsoft.com/technet/security/…n/ms06-016.mspx
V1.2: Revised due to issues discovered with the security update…
> Microsoft Windows Explorer
- http://www.microsoft.com/technet/security/…n/ms06-015.mspx
V2.0: Revised to inform customers that revised versions of the security update are available.
> Microsoft Internet Explorer 6.0 SP2
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-1992
Last revised: 4/26/2006
Source: US-CERT/NIST
Overview
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via nested OBJECT tags, which trigger invalid pointer dererences including NULL dereferences.
Impact
CVSS Severity: 8.0 (High)
Range: Remotely exploitable
Authentication: Not required to exploit
Impact Type: Provides user account access, Allows disruption of service…"