Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Windows_2000 | Microsoft | * | * |
| Windows_2003_server | Microsoft | sp2 (including) | sp2 (including) |
| Windows_98 | Microsoft | * | * |
| Windows_me | Microsoft | * | * |
| Windows_nt | Microsoft | * | * |
| Windows_vista | Microsoft | * | * |
| Windows_xp | Microsoft | * | * |