Vulnerability Name:

CVE-2009-3943 (CCN-54317)

Assigned:2009-11-08
Published:2009-11-08
Updated:2022-02-28
Summary:Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: BugTraq Mailing List, Sun Nov 08 2009 - 07:54:07 CST
DoS vulnerability in Internet Explorer

Source: MITRE
Type: CNA
CVE-2009-3943

Source: MISC
Type: Exploit, Third Party Advisory
http://websecurity.com.ua/3658/

Source: CCN
Type: Microsoft Web site
Internet Explorer

Source: CCN
Type: OSVDB ID: 60198
Microsoft IE DHTML Property setHomePage Method JavaScript Loop Remote DoS

Source: BUGTRAQ
Type: Broken Link, Third Party Advisory, VDB Entry
20091108 DoS vulnerability in Internet Explorer

Source: BUGTRAQ
Type: Broken Link, Third Party Advisory, VDB Entry
20091109 Re: Re: DoS vulnerability in Internet Explorer

Source: XF
Type: UNKNOWN
ie-sethomepage-dos(54317)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:internet_explorer:*:*:*:*:*:*:*:* (Version >= 6 and <= 6.0.2900.2180)

  • Configuration 2:
  • cpe:/a:microsoft:internet_explorer:*:*:*:*:*:*:*:* (Version >= 7.0 and <= 7.0.6000.16711)

  • Configuration CCN 1:
  • cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0.2800:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0.2600:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0.2800.1106:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0.2900.2180:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.0.5730.11:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.0:beta:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.00.5730.1100:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.00.6000.16386:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.00.6000.16441:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:7.0.5730:unknown:gold:*:*:*:*:*
  • OR cpe:/a:microsoft:ie:7.0.6000.16711:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft internet explorer *
    microsoft internet explorer *
    microsoft ie 6.0
    microsoft ie 6.0.2800
    microsoft ie 6.0.2600
    microsoft ie 6.0.2800.1106
    microsoft ie 6.0.2900.2180
    microsoft ie 7.0 beta2
    microsoft ie 7.0
    microsoft ie 7.0 beta1
    microsoft ie 7.0 beta3
    microsoft ie 6.0.2900
    microsoft ie 7.0.5730.11
    microsoft ie 7.0 beta
    microsoft ie 7.00.5730.1100
    microsoft ie 7.00.6000.16386
    microsoft ie 7.00.6000.16441
    microsoft ie 7.0.5730 unknown
    microsoft ie 7.0.6000.16711