<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx</link><description>You may have read reports of a new, irresponsibly disclosed vulnerability that affects IE 6.0 SP1. We are aware of this issue and are actively working on an update that addresses the problem, which was introduced with our last security update (MS06-042).</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Today's canceled re-release of MS06-042, and posting of a Security Advisory</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713227</link><pubDate>Wed, 23 Aug 2006 01:09:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713227</guid><dc:creator>Welcome to the Microsoft Security Response Center Blog!</dc:creator><description>&lt;br&gt;Hi everyone, Stephen Toulouse here.&amp;amp;amp;nbsp; We wanted to provide you with information about the MS06-042...</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713278</link><pubDate>Wed, 23 Aug 2006 02:01:01 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713278</guid><dc:creator>TJ</dc:creator><description>Although I'm not pleased with the issue and I’m sure many will slam you for it, I commend Microsoft for being upfront about it and keeping us informed (via this blog, MSRC blog, and TechNet). Many other software companies (who I shall not mention) could learn a lot by following suit. Over the years, Microsoft has become the leader in this area and thus the model.&lt;br&gt;&lt;br&gt;P.S. – mentioning the impact on beta software is greatly appreciated.</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713319</link><pubDate>Wed, 23 Aug 2006 02:34:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713319</guid><dc:creator>cooperpx</dc:creator><description>A mistake was made, a mistake will be cleaned up. Good. Accidents happen.&lt;br&gt;&lt;br&gt;However, lets drop off the righteousness tone for a second please? Microsoft is upset that somebody squealed on it. The word ETIQUETTE applies, not RESPONSIBILITY.&lt;br&gt;&lt;br&gt;I'd say that ETIQUETTE regarding security bugs is being redefined by people not of Microsoft.&lt;br&gt;&lt;br&gt;Might I suggest that IE gets its own out-of-band patching system, not restricted by any specific timing schedule, for home users and businesses with a local policy setting?</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713343</link><pubDate>Wed, 23 Aug 2006 02:46:02 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713343</guid><dc:creator>cooperpx</dc:creator><description>&amp;quot;For instance, we have code-reviewed the past ten months of code check-ins from the developer responsible for this issue.&amp;quot;&lt;br&gt;&lt;br&gt;- ouch Tony. I'm sure he/she feels bad enough! He/she likely had peer reviewers and they missed it too. Some stuff just slips by, even by really smart people with years of bug finding experience. I'd say your team was due for this kind of flaw and it happens ~ _even_ in open source! [sorry for the double post]&lt;br&gt;&lt;br&gt;&lt;br&gt;</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713442</link><pubDate>Wed, 23 Aug 2006 04:13:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713442</guid><dc:creator>Baillard</dc:creator><description>I posted a question to the MSRC Blog about the options that the Online Crash Analysis provides when IE fails due to the problems with MS06-042. &amp;nbsp; &amp;nbsp;Can you please provide links to MS06-042 from the OCA event page and other info such as assisting users in disabling HTTP 1.1? &amp;nbsp;The current info OCA suggests upgrading to XP SP2 (I do realize that SP1 support ends &amp;lt;60 days) is not the entire story.</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713572</link><pubDate>Wed, 23 Aug 2006 06:54:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713572</guid><dc:creator>redxii</dc:creator><description>For what reason would it affect SP1 but not SP2? Just curious.</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713585</link><pubDate>Wed, 23 Aug 2006 07:15:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713585</guid><dc:creator>Tony Chor [MSFT]</dc:creator><description>redxii: We changed some buffer sizes in SP2; the code was first fixed in SP2 and then ported down to SP1 without taking this change into consideration.&lt;br&gt;&lt;br&gt;baillard: Good idea re: updating our OCA response. I'll see what we can do here.&lt;br&gt;&lt;br&gt;cooperpx: I certainly didn't mean to imply that this developer was solely to blame. We just wanted to make sure there was nothing systemic about his changes that might pose a problem. we definitely tried to explore every avenue.&lt;br&gt;&lt;br&gt;cooperpx: We used to update IE on its own schedule, but many customers asked us to update IE at the same time as other updates so they could schedule and batch their testing and deployments. </description></item><item><title>Death toll rises due to FireFox</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713589</link><pubDate>Wed, 23 Aug 2006 07:21:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713589</guid><dc:creator>Brad</dc:creator><description>Did you guys see this?&lt;br&gt;Death toll rises due to FireFox&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://qainsight.net/2006/08/23/Death+Toll+Rises+Due+To+FireFox.aspx"&gt;http://qainsight.net/2006/08/23/Death+Toll+Rises+Due+To+FireFox.aspx&lt;/a&gt;</description></item><item><title>W2k SP4?</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713628</link><pubDate>Wed, 23 Aug 2006 07:52:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713628</guid><dc:creator>Tihiy</dc:creator><description>Sorry for buggin you but i'm unable to find exact information on bizzare lifecycle pages.&lt;br&gt;&lt;br&gt;IE6SP1 on XPSP1 support will be dropped in October, but what about IE6SP1 on W2KSP4? I guess it should be supported until W2K EOL, but when it ends?</description></item><item><title>Roman&amp;#8217;s Blog  &amp;raquo; Blog Archive   &amp;raquo; MS06-042 - more time needed&amp;#8230;</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713635</link><pubDate>Wed, 23 Aug 2006 08:04:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713635</guid><dc:creator>Roman’s Blog  » Blog Archive   » MS06-042 - more time needed…</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://blog.kluka.net/archives/19"&gt;http://blog.kluka.net/archives/19&lt;/a&gt;</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713781</link><pubDate>Wed, 23 Aug 2006 10:34:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713781</guid><dc:creator>Espen Antonsen, 24SevenOffice</dc:creator><description>Will this update fix the createPopup issue as well? A lot of our customers are reporting to us that IE is crashing when they use our web-application 24SevenOffice. This occurs due to a bug caused by using the createPopup function after the latest update is applied. This issue is not related to the IE6SP1/HTTP1.1 problem as the reports I have got customers used IE6SP2.&lt;br&gt;&lt;br&gt;Can you please make a statement to whether this issue will be fixed in the upcoming update?&lt;br&gt;&lt;br&gt;For more info and example see the following pages at comcept.net:&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.comcept.net/notify/kb918899/kb918899%20Statement.htm"&gt;http://www.comcept.net/notify/kb918899/kb918899%20Statement.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.comcept.net/crash.htm"&gt;http://www.comcept.net/crash.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;Thank you,&lt;br&gt;Espen Antonsen&lt;br&gt;24SevenOffice</description></item><item><title>Hotfix 923996 for popup issue</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713806</link><pubDate>Wed, 23 Aug 2006 10:53:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713806</guid><dc:creator>AH</dc:creator><description>There now is a hotfix available from Microsoft for the popup issue. It is so far only available through Microsoft support; you must call and ask for hotfix 923996 for Windows XP or for Windows 2003. Such calls into Microsoft are free.&lt;br&gt;As there are so many users suffering from this issue after deploying MS06-42, I would hope Microsoft includes the hotfix that fixes the popup issue into the re-release of MS06-42 as well.&lt;br&gt;</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#713843</link><pubDate>Wed, 23 Aug 2006 11:19:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:713843</guid><dc:creator>Espen Antonsen, 24SevenOffice</dc:creator><description>AH, thank you very much for that information. Unfortuanly the fix is only available in English and Japanese. We have a lot of customers in Norway who are complaining about this issue and it seems like they have to wait for the next update.&lt;br&gt;&lt;br&gt;Cheers,&lt;br&gt;Espen Antonsen&lt;br&gt;24SevenOffice</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#714482</link><pubDate>Wed, 23 Aug 2006 15:54:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:714482</guid><dc:creator>Can i post this blog?</dc:creator><description>test</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#714717</link><pubDate>Wed, 23 Aug 2006 17:25:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:714717</guid><dc:creator>ali</dc:creator><description>se contacter</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#714857</link><pubDate>Wed, 23 Aug 2006 18:45:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:714857</guid><dc:creator>Steve Young</dc:creator><description>First time to be here ^_^</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#714865</link><pubDate>Wed, 23 Aug 2006 18:52:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:714865</guid><dc:creator>Vince</dc:creator><description>I was under the impression that IE7 had removed the createPopup call from standard web page designs? (e.g. not an embedded app, using the IE engine)&lt;br&gt;&lt;br&gt;Can an MS team member clarify if this happened or not?&lt;br&gt;&lt;br&gt;From a web user perspective, these popups are the most anoying ever, since they are chromeless, z-ordered on top of everything, and are full screen, not just in the IE viewport.&lt;br&gt;&lt;br&gt;If not, can the developers clarify if these are 100% blockable by type, in IE7?&lt;br&gt;&lt;br&gt;E.g. I may want a popup window to choose a date in my online airfare search, but I will never want a &amp;quot;.createPopop()&amp;quot; call to be enabled.&lt;br&gt;&lt;br&gt;Thanks Vince.</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#714868</link><pubDate>Wed, 23 Aug 2006 18:57:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:714868</guid><dc:creator>Christopher Vaughan [MSFT]</dc:creator><description>Tihiy - I blogged about this at &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/ie/archive/2005/03/29/403513.aspx"&gt;http://blogs.msdn.com/ie/archive/2005/03/29/403513.aspx&lt;/a&gt;. Essentially, IE6SP1 on Win2k SP4 will be supported until Win2k expires.&lt;br&gt;&lt;br&gt;Espen - You can have your TAM contact Microsoft to request a localized version of the hotfix. The re-release of this update is for IE6SP1 only and the issue you're seeing is for XPSP2, so therefore the re-release will not fix that issue as it's on a different platform.</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#714947</link><pubDate>Wed, 23 Aug 2006 19:55:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:714947</guid><dc:creator>DMassy</dc:creator><description>Vince,&lt;br&gt;createPopup has not been disable in IE7. It is actually useful functionality for example to produce rich tooltips in web solutions.&lt;br&gt;There were restrictions put on this functionality in Windows XP SP2 to ensure that they cannot display outside of the HTML display area of the browser and confuse people. Maybe that is what you are thinking of.&lt;br&gt;Thanks&lt;br&gt;-Dave</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#715708</link><pubDate>Thu, 24 Aug 2006 03:26:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:715708</guid><dc:creator>Tom</dc:creator><description>@dave&lt;br&gt;&lt;br&gt;I don't see how a &amp;lt; div &amp;gt; can't do anything that createPopup() can.&lt;br&gt;&lt;br&gt;Oh well, guess I'll go look into writing an extension for IE7 to block these.&lt;br&gt;&lt;br&gt;@Vince&lt;br&gt;Can I send you a link to it when I'm done? :-)</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#716330</link><pubDate>Thu, 24 Aug 2006 09:16:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:716330</guid><dc:creator>William Lefkovics</dc:creator><description>Tony, by &amp;quot;irresponsibly disclosed&amp;quot; are you referring to the reference to &amp;quot;Long URLs&amp;quot; outlined in KB 923762? &amp;nbsp; &amp;nbsp; &amp;nbsp;(&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/technet/security/advisory/923762.mspx"&gt;http://www.microsoft.com/technet/security/advisory/923762.mspx&lt;/a&gt;)&lt;br&gt;&lt;br&gt;</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#716472</link><pubDate>Thu, 24 Aug 2006 10:13:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:716472</guid><dc:creator>lamon</dc:creator><description>Hello,everyone,I'm a security engineer from one of your enterprise customers.After deploying MS06-042,when our users access to PeopleSoft(HR System),IE would breakdown.It occur that the OS is win2000 and XP without SP2.&lt;br&gt;We are in china ,most of our OS language is chinese.Microsoft(China) MSTC engineers told us that they are not sure when you could release the patch's patch to fix up our trouble.They sent us a tool to have a try,but just the english version,could you speed up the development of the chinese version ?Thanks.</description></item><item><title>Use Firefox .... and all its fine ...</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#716816</link><pubDate>Thu, 24 Aug 2006 13:00:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:716816</guid><dc:creator>ZOC</dc:creator><description>Dont use the false browser ... </description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#716879</link><pubDate>Thu, 24 Aug 2006 13:59:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:716879</guid><dc:creator>Espen Antonsen</dc:creator><description>@Christopher Vaughan [MSFT]&lt;br&gt;I have called Microsoft support here in Norway and hopefully they will provide me with a localized version of the hotfix. I think this bug is very critical - will the hotfix really not be released through windows update?&lt;br&gt;&lt;br&gt;@Tom&lt;br&gt;createPopup will be displayed over iframes, frames and outside the window. It is very useful when creating a contextMenu.&lt;br&gt;&lt;br&gt;Espen Antonsen&lt;br&gt;24SevenOffice</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#717060</link><pubDate>Thu, 24 Aug 2006 16:12:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:717060</guid><dc:creator>Van Der Beek Philip</dc:creator><description>I want to have IE 6.0 SP1 for update thankyou if you am having Xp Home weather can or not please tell me or send me a CD to me thankyou </description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#717435</link><pubDate>Thu, 24 Aug 2006 17:59:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:717435</guid><dc:creator>Tom</dc:creator><description>@Espen&lt;br&gt;&lt;br&gt;In Dave Massey's comment (above mine, to Vince)&lt;br&gt;&lt;br&gt;It sounds like IE7 has cleaned the createPopup() call a bit, to ensure it _CANT_ display beyond the viewport boundary.&lt;br&gt;&lt;br&gt;It again, should be noted, that in all browsers, you can float a div over any content on the page to crate a contextmenu or similar. &amp;nbsp;The only catches are:&lt;br&gt;1.) in IE 6 or below, you need to float an iframe under the div because the select element was incorrectly coded to be at the window level. (fixed in IE7 thankfully!!!)&lt;br&gt;2.) in a frameset (not iframes), you can't float anything over frames, because there is no (top level) document body to attach the div to.&lt;br&gt;&lt;br&gt;Tom</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#717602</link><pubDate>Thu, 24 Aug 2006 18:38:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:717602</guid><dc:creator>Christopher Vaughan [MSFT]</dc:creator><description>Espen: hotfixes are never released through Windows Update. If you get a hotfix via our support centers, you'll be pointed to a separate download. However, in a subsequent security update, your hotfix should be automatically included so you won't have to re-apply the hotfix again.&lt;br&gt;&lt;br&gt;lamon: when we release security updates, all languages are released at the same time. The Chinese version of the re-release of MS06-042 should already be available via Windows Update.</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#718193</link><pubDate>Thu, 24 Aug 2006 19:57:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:718193</guid><dc:creator>Ottmar Freudenberger</dc:creator><description>I wonder why there's no new blog entry to be found (yet) here about the release of KB918899v2 for IE6 SP1:&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c335caa9-b9e6-403d-a039-2d3dca723653"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=c335caa9-b9e6-403d-a039-2d3dca723653&lt;/a&gt;&lt;br&gt;&lt;br&gt;Bye,&lt;br&gt;Freudi</description></item><item><title>Update Available for IE 6.0 SP1 Security Vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#718216</link><pubDate>Thu, 24 Aug 2006 20:00:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:718216</guid><dc:creator>IEBlog</dc:creator><description>&lt;br&gt;This morning we re-released our August security update (MS06-042) for IE 6.0 SP1. This update is available...</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#718725</link><pubDate>Thu, 24 Aug 2006 21:55:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:718725</guid><dc:creator>MikeG</dc:creator><description>When a patch is released how soon after will the wsusscan.cab file be updated for SMS ITMU custumers?&lt;br&gt;&lt;br&gt;Thanks&lt;br&gt;Mike</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#718727</link><pubDate>Thu, 24 Aug 2006 21:56:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:718727</guid><dc:creator>Zach</dc:creator><description>--&amp;gt; It sounds like IE7 has cleaned the createPopup() call a bit, to ensure it _CANT_ display beyond the viewport boundary. &lt;br&gt;&lt;br&gt;&lt;br&gt;Is this in all environments, or in a trusted environment can you still extend beyond the boundry.&lt;br&gt;&lt;br&gt;Ask because I have GUI dependent on that - and by trusted - I mean trusted to the point that its being served in my own wrapped Webbrowser control</description></item><item><title>Symphonious  &amp;raquo; Don&amp;#8217;t Blame The Committer</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#722501</link><pubDate>Fri, 25 Aug 2006 14:11:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:722501</guid><dc:creator>Symphonious  » Don’t Blame The Committer</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://www.symphonious.net/2006/08/25/dont-blame-the-committer/"&gt;http://www.symphonious.net/2006/08/25/dont-blame-the-committer/&lt;/a&gt;</description></item><item><title>Update waiting for IE 6.0 SP2 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#724398</link><pubDate>Fri, 25 Aug 2006 23:09:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:724398</guid><dc:creator>ST</dc:creator><description>923996 When you visit a Web page that uses a custom pop-up object,&lt;br&gt;Internet Explorer 6 closes unexpectedly&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/923996/"&gt;http://support.microsoft.com/kb/923996/&lt;/a&gt;&lt;br&gt;&lt;br&gt;IE6SP2(XPSP2 or 2003SP1) + 918899(MS06-042)&lt;br&gt;createPopup()</description></item><item><title>&amp;quot;eEye y Microsoft... en pie de guerra&amp;quot; - Foro de Spyware</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#725859</link><pubDate>Sun, 27 Aug 2006 02:03:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:725859</guid><dc:creator>"eEye y Microsoft... en pie de guerra" - Foro de Spyware</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://www.forospyware.com/t49191.html#post203361"&gt;http://www.forospyware.com/t49191.html#post203361&lt;/a&gt;</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#729363</link><pubDate>Tue, 29 Aug 2006 06:09:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:729363</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>@Zach: The CreatePopup call is restricted for content in the Internet zone. &amp;nbsp;I suspect the limitation only applies to the Internet Explorer process unless you opt your process into the feature.</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#729520</link><pubDate>Tue, 29 Aug 2006 09:14:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:729520</guid><dc:creator>security program</dc:creator><description>see all kinds of security program!&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.shareware123.com/utility/security_encryption/index_69.htm"&gt;http://www.shareware123.com/utility/security_encryption/index_69.htm&lt;/a&gt;</description></item><item><title>Bolet&amp;amp;#237;n 00066 - 29/08/2006</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#730151</link><pubDate>Tue, 29 Aug 2006 18:58:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:730151</guid><dc:creator>Weblog de Mauricio (W.O.L.F.) R. Arreola González</dc:creator><description>1.- El parche que llego el martes pasado es tambien para Windows Vista2.- Corrupcion de memoria en Firefox...</description></item><item><title>re: Update coming for IE 6.0 SP1 security vulnerability</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#735828</link><pubDate>Fri, 01 Sep 2006 23:51:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:735828</guid><dc:creator>Zach</dc:creator><description>@EricLaw - Thanks :) &lt;br&gt;&lt;br&gt;For a second there thought I would have to redo my menus and other parts of the toolbars.</description></item><item><title>Update Available for IE 5.01, IE 6.0 SP1, and IE 6.0 on Server 2003</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#750820</link><pubDate>Tue, 12 Sep 2006 20:01:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:750820</guid><dc:creator>IEBlog</dc:creator><description>&lt;br&gt;This morning we re-released three versions of our August 2006 cumulative security update (MS06-042)....</description></item><item><title>newsBreaks.net &amp;raquo; Update: Microsoft&amp;#8217;s August IE patch contains security bug</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#758418</link><pubDate>Sun, 17 Sep 2006 05:21:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:758418</guid><dc:creator>newsBreaks.net » Update: Microsoft’s August IE patch contains security bug</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://newsbreaks.net/archives/5323"&gt;http://newsbreaks.net/archives/5323&lt;/a&gt;</description></item><item><title>internet explorer 6 0</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#8454377</link><pubDate>Sat, 03 May 2008 12:44:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8454377</guid><dc:creator>internet explorer 6 0</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://raul.infomediaguide.com/internetexplorer60.html"&gt;http://raul.infomediaguide.com/internetexplorer60.html&lt;/a&gt;&lt;/p&gt;
</description></item><item><title> IEBlog Update coming for IE 6 0 SP1 security vulnerability | Paid Surveys</title><link>http://blogs.msdn.com/ie/archive/2006/08/22/711402.aspx#9660015</link><pubDate>Sat, 30 May 2009 01:55:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9660015</guid><dc:creator> IEBlog Update coming for IE 6 0 SP1 security vulnerability | Paid Surveys</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://paidsurveyshub.info/story.php?title=ieblog-update-coming-for-ie-6-0-sp1-security-vulnerability"&gt;http://paidsurveyshub.info/story.php?title=ieblog-update-coming-for-ie-6-0-sp1-security-vulnerability&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>