The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."
| Software | From | Fixed in |
|---|---|---|
| microsoft / internet_explorer | 5.01-sp4 | 5.01-sp4.x |
| microsoft / internet_explorer | 6-sp1 | 6-sp1.x |
| microsoft / windows_2000 | - | - |
| microsoft / internet_explorer | 6 | 6.x |
| microsoft / windows_xp | - | - |