CVE-2002-0026

Internet Explorer 5.5 and 6.0 - Remote Code Execution via Asynchronous Event Handling

Title source: llm
STIX 2.1

Description

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A32
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A23
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4082

Scores

EPSS 0.1333
EPSS Percentile 96.0%

Details

Status published
Products (2)
microsoft/internet_explorer 5.5
microsoft/internet_explorer 6.0
Published Mar 08, 2002
Tracked Since Feb 18, 2026