CVE-2000-0768

Internet Explorer <5.x - Info Disclosure

Title source: llm
STIX 2.1

Description

A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.

References (2)

Core 2
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1564

Scores

EPSS 0.0951
EPSS Percentile 95.0%

Details

Status published
Products (5)
microsoft/ie 4.0 (2 CPE variants)
microsoft/ie 5.0 (4 CPE variants)
microsoft/internet_explorer 4.0
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.5
Published Oct 20, 2000
Tracked Since Feb 18, 2026