CVE-2006-1992 describes a denial-of-service vulnerability in Microsoft Internet Explorer, specifically in mshtml.dll version 6.00.2900.2873, where remote attackers can crash the browser by nesting OBJECT tags, leading to invalid pointer dereferences. The vulnerability has a low CVSS score of 2.6, indicating a network-based attack with high complexity and a potential impact of only denial of service, as Microsoft has stated it is not exploitable for code execution. While there is an ExploitDB entry for memory corruption, there are no Metasploit or Nuclei modules, and the CVE shows no active exploitation, community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.2900CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.