CVE-2000-0464: Buffer Overflow
Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Internet Explorer 4.x/5.xfrom your environment.Uninstall Internet Explorer 4.x and 5.x from affected systems if practical (replace with a non-affected browser or a newer, supported product).
- Configuration
Disable or restrict ActiveX controls in Internet Explorer to prevent parsing of malformed component attributes that can trigger the buffer overflow.
Internet Explorer (ActiveX) ActiveX parameter parsing = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0464?
CVE-2000-0464 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2000-0464?
To fix CVE-2000-0464, upgrade to a non-vulnerable version of Internet Explorer, preferably at least version 5.5 or higher.
What software is affected by CVE-2000-0464?
CVE-2000-0464 affects Internet Explorer versions 4.0, 4.0.1, 5.0, and 5.01.
What type of vulnerability is CVE-2000-0464?
CVE-2000-0464 is a buffer overflow vulnerability that can lead to arbitrary command execution.
Can CVE-2000-0464 be exploited remotely?
Yes, CVE-2000-0464 can be exploited remotely by an attacker through specially crafted ActiveX controls.