CVE-2000-0596

Internet Explorer 5.x - Remote Code Execution via ActiveX OBJECT Tag

Title source: llm
STIX 2.1

Description

Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1398
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=39589359.762392DB%40nat.bg
US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2000-16.html

Scores

EPSS 0.2477
EPSS Percentile 97.7%

Details

Status published
Products (2)
microsoft/internet_explorer 4.0.1 sp2
microsoft/internet_explorer 5
Published Jun 27, 2000
Tracked Since Feb 18, 2026