CVE Vulnerabilities

CVE-2005-1990

Published: Aug 10, 2005 | Modified: Jul 23, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka COM Object Instantiation Memory Corruption Vulnerability, a different vulnerability than CVE-2005-2087.

Affected Software

Name Vendor Start Version End Version
Ie Microsoft 6-windows_server_2003_sp1 (including) 6-windows_server_2003_sp1 (including)
Internet_explorer Microsoft 5.01 (including) 5.01 (including)
Internet_explorer Microsoft 5.5 (including) 5.5 (including)

References