CVE-2000-0768: Low severity Microsoft ie vulnerability
Published Oct 13, 2000
·Updated
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
Affected Software
9 affected components
Microsoft ie=5.0
Microsoft ie=4.0
Microsoft ie=5.0
Microsoft ie=5.0
Microsoft ie=4.0
Microsoft ie=5.0
Microsoft Internet Explorer=5.01
Microsoft Internet Explorer=4.0
Microsoft Internet Explorer=5.5
Remediation
Patch Available
Event History
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0768?
CVE-2000-0768 is considered a critical vulnerability as it allows remote attackers to access client files.
2
How do I fix CVE-2000-0768?
To fix CVE-2000-0768, users should upgrade to a later version of Internet Explorer that addresses this vulnerability.
3
What versions of Internet Explorer are affected by CVE-2000-0768?
CVE-2000-0768 affects Internet Explorer versions 4.x and 5.x.
4
What type of attack is associated with CVE-2000-0768?
CVE-2000-0768 is associated with cross-site scripting attacks due to improper domain verification.
5
Can CVE-2000-0768 be exploited remotely?
Yes, CVE-2000-0768 can be exploited remotely without requiring direct access to the affected system.