Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the COM Object Instantiation Memory Corruption Vulnerability, a different vulnerability than CVE-2005-2127.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ie | Microsoft | 6.0-sp1 (including) | 6.0-sp1 (including) |
Ie | Microsoft | 6.0-sp2 (including) | 6.0-sp2 (including) |
Internet_explorer | Microsoft | 5.0.1 (including) | 5.0.1 (including) |
Internet_explorer | Microsoft | 5.0.1-sp1 (including) | 5.0.1-sp1 (including) |
Internet_explorer | Microsoft | 5.0.1-sp2 (including) | 5.0.1-sp2 (including) |
Internet_explorer | Microsoft | 5.0.1-sp3 (including) | 5.0.1-sp3 (including) |
Internet_explorer | Microsoft | 5.0.1-sp4 (including) | 5.0.1-sp4 (including) |
Internet_explorer | Microsoft | 5.5 (including) | 5.5 (including) |
Internet_explorer | Microsoft | 5.5-sp1 (including) | 5.5-sp1 (including) |
Internet_explorer | Microsoft | 5.5-sp2 (including) | 5.5-sp2 (including) |
Internet_explorer | Microsoft | 6.0 (including) | 6.0 (including) |