CVE-1999-0347: Critical severity Microsoft Internet Explorer vulnerability

Published Jan 26, 1999
·
Updated

Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

Affected Software

1 affected component
Microsoft Internet Explorer

Event History

Jan 26, 1999
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionWeakness
Data Sourced
05:00 AM
Severity
Data Sourced
via NVD·05:00 AM
DescriptionSeverity
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0347?

CVE-1999-0347 is classified as a critical vulnerability due to its potential for remote file reading and spoofing attacks.

2

How do I fix CVE-1999-0347?

To fix CVE-1999-0347, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.

3

What type of attacks can be performed using CVE-1999-0347?

Attackers can exploit CVE-1999-0347 to read local files and spoof web pages, potentially leading to information disclosure.

4

Are all versions of Internet Explorer affected by CVE-1999-0347?

CVE-1999-0347 specifically affects Internet Explorer 4.01 and may not impact later versions.

5

What should I do if I cannot update Internet Explorer to mitigate CVE-1999-0347?

If updating is not possible, avoid using Internet Explorer 4.01 for browsing and consider using an alternative browser.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203