Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
Use CWE-94, Microsoft vendor hub and Ie product page to widen CVE-2006-3730 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-0552, CVE-2012-1545 and CVE-2009-2069 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.