CVE-2003-0532

Internet Explorer 5.01 SP3-6.0 SP1 - Remote Code Execution

Title source: manual
STIX 2.1

Description

Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.

References (5)

Core 5
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/865940
Exploit, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106149026621753&w=2

Scores

EPSS 0.2296
EPSS Percentile 97.5%

Details

Status published
Products (4)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 5.0.1 (4 CPE variants)
microsoft/internet_explorer 5.5 (3 CPE variants)
microsoft/internet_explorer 6.0
Published Aug 27, 2003
Tracked Since Feb 18, 2026