CVE Vulnerabilities

CVE-2005-0054

Published: May 02, 2005 | Modified: Jul 23, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the URL Decoding Zone Spoofing Vulnerability.

Affected Software

Name Vendor Start Version End Version
Ie Microsoft 6-windows_server_2003_sp1 (including) 6-windows_server_2003_sp1 (including)
Internet_explorer Microsoft 5.01 (including) 5.01 (including)
Internet_explorer Microsoft 5.5 (including) 5.5 (including)

References