Vulnerabilities > CVE-2005-0553 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
microsoft
exploit available

Summary

Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".

Exploit-Db

descriptionMicrosoft Internet Explorer 5.0.1 DHTML Object Race Condition Memory Corruption Vulnerability. CVE-2005-0553. Remote exploit for windows platform
idEDB-ID:25386
last seen2016-02-03
modified2005-04-12
published2005-04-12
reporterBerend-Jan Wever
sourcehttps://www.exploit-db.com/download/25386/
titleMicrosoft Internet Explorer 5.0.1 DHTML Object Race Condition Memory Corruption Vulnerability

Oval

  • accepted2014-02-24T04:00:22.025-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionRace condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
    familywindows
    idoval:org.mitre.oval:def:1695
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleDHTML Object Memory Corruption Vulnerability (IE6 for XP,SP2)
    version67
  • accepted2014-02-24T04:03:14.323-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionRace condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
    familywindows
    idoval:org.mitre.oval:def:3100
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleDHTML Object Memory Corruption Vulnerability (IE6 for Server 2003)
    version68
  • accepted2014-02-24T04:03:16.864-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameJason Spashett
      organizationCentennial Software
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionRace condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
    familywindows
    idoval:org.mitre.oval:def:3752
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleDHTML Object Memory Corruption Vulnerability (IE6,SP1)
    version68
  • accepted2014-02-24T04:03:19.990-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionRace condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
    familywindows
    idoval:org.mitre.oval:def:4874
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleDHTML Object Memory Corruption Vulnerability (IE5.01,SP3)
    version67
  • accepted2014-02-24T04:03:20.603-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionRace condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
    familywindows
    idoval:org.mitre.oval:def:4985
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleDHTML Object Memory Corruption Vulnerability (IE5.01,SP4)
    version67

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/37192/ie_dhtml_poc.txt
idPACKETSTORM:37192
last seen2016-12-05
published2005-04-18
reporterSkyLined
sourcehttps://packetstormsecurity.com/files/37192/ie_dhtml_poc.txt.html
titleie_dhtml_poc.txt

Saint

bid13120
descriptionInternet Explorer DHTML object vulnerability
idwin_patch_ie_url
osvdb15465
titleie_dhtml_object
typeclient