CVE-2000-0028: Low severity Microsoft ie vulnerability
Published Dec 23, 1999
·Updated
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
Affected Software
11 affected components
Microsoft ie=4.0-a_mac_os
Microsoft Internet Explorer=3.0.2
Microsoft Internet Explorer=3.0
Microsoft Internet Explorer=3.1
Microsoft Internet Explorer=3.2
Microsoft Internet Explorer=4.0
Microsoft Internet Explorer=4.0.1-sp2
Microsoft Internet Explorer=4.1
Microsoft Internet Explorer=4.5
Microsoft Internet Explorer=5.0
Microsoft Internet Explorer=5.1
Event History
Dec 23, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0028?
The severity of CVE-2000-0028 is rated as moderate due to its ability to bypass security features in Internet Explorer.
2
How do I fix CVE-2000-0028?
To fix CVE-2000-0028, users should upgrade to the latest version of Internet Explorer or apply any available security patches from Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2000-0028?
CVE-2000-0028 affects Internet Explorer versions 3.0 to 5.1.
4
Can CVE-2000-0028 be exploited remotely?
Yes, CVE-2000-0028 can be exploited remotely allowing attackers to bypass cross-frame security.
5
What does CVE-2000-0028 allow attackers to do?
CVE-2000-0028 allows attackers to read files on the user's system by bypassing security policies.