CVE-2001-0919: Medium severity Microsoft Internet Explorer vulnerability
Published Nov 26, 2001
·Updated
Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.
Affected Software
1 affected component
Microsoft Internet Explorer=5.5
Event History
Nov 26, 2001
CVE Published
05:00 AM
Feb 2, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0919?
CVE-2001-0919 is classified as a moderate severity vulnerability because it allows cookies to be set via JavaScript without user warning.
2
How do I fix CVE-2001-0919?
To fix CVE-2001-0919, consider upgrading to a later version of Internet Explorer that does not have this vulnerability.
3
Who is affected by CVE-2001-0919?
CVE-2001-0919 affects users of Internet Explorer 5.5 on Windows ME with specific cookie settings enabled.
4
What type of attack does CVE-2001-0919 facilitate?
CVE-2001-0919 can facilitate attacks involving the unauthorized setting of cookies through JavaScript.
5
Is there a workaround for CVE-2001-0919?
A potential workaround for CVE-2001-0919 is to disable JavaScript in the Internet Explorer settings.