CVE-2004-0284

Microsoft Internet Explorer 6.0 - Denial of Service via Null Character Sequence

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.

References (3)

Core 3
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9629
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15127
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=107643134712133&w=2

Scores

EPSS 0.1677
EPSS Percentile 96.7%

Details

Status published
Products (4)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 6.0
microsoft/outlook 2002 (3 CPE variants)
microsoft/outlook 2003
Published Nov 23, 2004
Tracked Since Feb 18, 2026