>> Microsoft Internet Explorer "DirectAnimation" Control Denial of Service Vulnerability
Title : Microsoft Internet Explorer "DirectAnimation" Control Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-2719 CVE ID : CVE-2006-3513
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-09
Technical Description
A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to cause a denial of service. This flaw is due to a NULL pointer dereference error in the DirectAnimation control ("danim.dll") when referencing a non-initialized "Data" property of a "DAUserData" object, which could be exploited by attackers to crash a vulnerable browser by tricking a user into visiting a malicious web page.