AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2004-2434

MEDIUM · CVSS 5 EPSS 32.76%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-12-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2004-2434
Severity
MEDIUM
CVSS
5
EPSS
32.76%
Microsoft

Original NVD Description

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.