CVE-2001-0332: Medium severity Microsoft Internet Explorer vulnerability
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0332?
CVE-2001-0332 has a medium severity rating due to its capability to allow unauthorized access to local files.
How do I fix CVE-2001-0332?
To fix CVE-2001-0332, it is recommended to upgrade to a later version of Internet Explorer than 5.5.
Which versions of Internet Explorer are affected by CVE-2001-0332?
CVE-2001-0332 affects Internet Explorer versions 5.01 and 5.5.
What is the impact of CVE-2001-0332?
The impact of CVE-2001-0332 allows attackers to read certain files on a client computer through cross-domain frame manipulation.
Is there a workaround for CVE-2001-0332?
There are no official workarounds for CVE-2001-0332; upgrading to a more secure version is the only recommended action.