CVE-2006-3729 describes a denial-of-service vulnerability in Internet Explorer 6 on Windows XP SP2, specifically when Microsoft Office is installed. An attacker can crash the browser by providing a large negative integer to the getDataMemberName method of the OWC11.DataSourceControl.11 object, leading to an integer overflow and null dereference. This vulnerability has a low CVSS score of 2.6, indicating a network-based attack with high complexity and a partial availability impact. While not actively exploited in the wild or on the KEV catalog, a proof-of-concept exploit exists on ExploitDB, but there is no evidence of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6.0:sp1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6.0:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.