First published: Fri Mar 08 2002(Updated: )
Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0022 is classified as a critical vulnerability due to its ability to allow remote code execution.
To fix CVE-2002-0022, upgrade to a newer version of Internet Explorer that is not affected, such as Internet Explorer 7 or later.
Users of Internet Explorer versions 5.5 and 6.0 on Windows operating systems are affected by CVE-2002-0022.
CVE-2002-0022 is a buffer overflow vulnerability that can be exploited through specially crafted web pages.
Yes, CVE-2002-0022 can be exploited remotely by attackers through the use of malicious web pages.