Denial of Service Vulnerability in Outlook Express Address Book for Internet Explorer 6
CVE-2005-4840

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
31 December 2005

Summary

The Outlook Express Address Book control, when used in conjunction with Internet Explorer 6, is susceptible to a denial of service attack. This flaw allows remote attackers to create a harmful OutlookExpress.AddressBook COM object. As a result, an attacker can trigger a NULL dereference, leading to a crash of the browser and disrupting service. This vulnerability highlights the risks associated with integrating COM objects into web applications, particularly in outdated browsers.

References

EPSS Score

28% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.