Description
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
References (5)
Core 5
Core References
Various Sources x_refsource_misc
http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.cert.org/advisories/CA-2000-10.html
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-039
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1309
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/4627
Scores
EPSS
0.0483
EPSS Percentile
91.2%
Details
Status
published
Products (5)
microsoft/ie
4.0 (2 CPE variants)
microsoft/ie
4.0.1 (3 CPE variants)
microsoft/ie
5.0 (4 CPE variants)
microsoft/ie
5.0.1 (4 CPE variants)
microsoft/internet_explorer
4.0
Published
Jun 05, 2000
Tracked Since
Feb 18, 2026