PT-2005-1175 · Microsoft · Internet Explorer
Andreas Sandblad
·
Published
2005-02-08
·
Updated
2021-07-23
·
CVE-2005-0055
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 5.01, 5.5, and 6
Description
The issue arises from improper buffer validation when handling certain DHTML methods, including the
createControlRange Javascript function. This allows remote attackers to execute arbitrary code.Recommendations
For Internet Explorer versions 5.01, 5.5, and 6, consider disabling the
createControlRange Javascript function as a temporary workaround until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer