Unbelievable effort to support tags in IE ;-)

This is a funny bug found in Internet Explorer (and all other software where the HTML rendering libraries are used, such as Outlook and co.).

By including &ltinput type crash> in your HTML code, it is actually possible to get Internet Explorer & co to crash! Talk about compliance.

Check out the bug report: Secunia – Advisories – Microsoft Shell Light-Weight Utility Library Denial of Service

Reportedly, the vulnerability can be exploited to crash the following applications:

– Windows Explorer

– Internet Explorer

– Outlook

– Outlook Express

– Frontpage

NOTE: Other applications may also be affected.


There is no immidiate solution available.

If this is regarded as a serious risk, then don’t view untrusted HTML documents. Use another browser that isn’t linked to the vulnerable library when surfing the Internet.

Yet another good reason to switch to Opera!

Disclaimer: I am norwegian, and so is Opera Software. Unfortunately I don’t own any stocks in the company ;-)

8 thoughts on “Unbelievable effort to support tags in IE ;-)”

  1. ooops. the comments stripped the html.

    You dont need the crash, only this: &ltinput type&gt

  2. I tried that on all my browsers and they didn’t crash? You sure its [input type nothing] (replaced the square brackets with the normal HTML brackets..)

  3. You starting to promote Opera, Jarle? :)

    Disclaimer: Not Norwegian, don’t own stocks in Opera, but do work for them ;-)

  4. Hi Remco, Opera is a great browser and I have been pushing it whenever I have had the chance. With 7 it has really become a grown up browser with a lot of UI enhancements that I miss in other browsers (I am sure Microsoft will follow with gestures pretty soon).

    The amazing thing is that the browser is still lightening fast, even with its amazing CSS/HTML rendering support. The only thing I miss is support for XML. Its nice to be able to browse XML documents as threes in IE, would have been great with something simular in Opera.

