CVE-1999-1093

Internet Explorer < 4.0.1 - Remote Code Execution via Window.External Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/support/kb/articles/q191/2/00.asp
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/1276.php

Scores

EPSS 0.1255
EPSS Percentile 95.8%

Details

Status published
Products (3)
microsoft/internet_explorer 4.0
microsoft/internet_explorer 4.0.1
microsoft/internet_explorer < 4.0.1
Published Dec 31, 1999
Tracked Since Feb 18, 2026