CVE-2003-0532
Internet Explorer 5.01 SP3-6.0 SP1 - Remote Code Execution
Title source: manualDescription
Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.
References (5)
Core 5
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/865940
Various Sources x_refsource_misc
http://www.eeye.com/html/Research/Advisories/AD20030820.html
Exploit, Vendor Advisory mailing-list
x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106149026621753&w=2
Scores
EPSS
0.2296
EPSS Percentile
97.5%
Details
Status
published
Products (4)
microsoft/ie
6.0 sp1
microsoft/internet_explorer
5.0.1 (4 CPE variants)
microsoft/internet_explorer
5.5 (3 CPE variants)
microsoft/internet_explorer
6.0
Published
Aug 27, 2003
Tracked Since
Feb 18, 2026