VULNERABILITY INTELLIGENCE

CVE-2004-2011

CVSS score2.6 LOW
EPSS probability7.41%
CISA KEVNot currently listed
Published2004-12-31
Last modified2026-06-16
CVSS vectorAV:N/AC:H/Au:N/C:N/I:N/A:P

Description

msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI.

Primary references