Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
- http://isc.sans.org/diary.php?storyid=1742
- https://www.exploit-db.com/exploits/2440
No PoCs found on GitHub currently.