CVE-2000-0596
Internet Explorer 5.x - Remote Code Execution via ActiveX OBJECT Tag
Title source: llmDescription
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=000d01bfe0fb%24418f59b0%2496217aa8%40src.bu.edu
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1398
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-049
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=39589359.762392DB%40nat.bg
US Government Resource third-party-advisory
x_refsource_cert
http://www.cert.org/advisories/CA-2000-16.html
Scores
EPSS
0.2477
EPSS Percentile
97.7%
Details
Status
published
Products (2)
microsoft/internet_explorer
4.0.1 sp2
microsoft/internet_explorer
5
Published
Jun 27, 2000
Tracked Since
Feb 18, 2026