Vulnerabilities > CVE-2005-0554 - Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."

Exploit-Db

descriptionMS Internet Explorer DHTML Object Handling Vulns (MS05-020). CVE-2005-0554. Dos exploit for windows platform
idEDB-ID:931
last seen2016-01-31
modified2005-04-12
published2005-04-12
reporterSkylined
sourcehttps://www.exploit-db.com/download/931/
titleMicrosoft Internet Explorer DHTML Object Handling Vulns MS05-020

Oval

  • accepted2014-02-24T04:00:10.022-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionBuffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:1196
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleURL Parsing Memory Corruption Vulnerability (IE5.01,SP3)
    version67
  • accepted2014-02-24T04:03:11.830-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionBuffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:2253
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleURL Parsing Memory Corruption Vulnerability (IE5.01,SP4)
    version67
  • accepted2014-02-24T04:03:13.097-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionBuffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:2559
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleURL Parsing Memory Corruption Vulnerability (IE6 for Server 2003)
    version68
  • accepted2014-02-24T04:03:17.037-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionBuffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:3817
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleURL Parsing Memory Corruption Vulnerability (IE6 for XP,SP2)
    version67
  • accepted2014-02-24T04:03:27.309-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameJason Spashett
      organizationCentennial Software
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionBuffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:789
    statusaccepted
    submitted2005-05-10T12:00:00.000-04:00
    titleURL Parsing Memory Corruption Vulnerability (IE6,SP1)
    version68