CVE-1999-1087

Internet Explorer 4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
http://www.microsoft.com/Windows/Ie/security/dotless.asp
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/7828
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/support/kb/articles/q168/6/17.asp
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/2209

Scores

EPSS 0.0628
EPSS Percentile 92.9%

Details

Status published
Products (2)
microsoft/internet_explorer 4.0
microsoft/internet_explorer 4.0.1 (2 CPE variants)
Published Dec 31, 1999
Tracked Since Feb 18, 2026