First published: Tue Jun 11 2002(Updated: )
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0461 has a low severity rating as it causes a denial of service without compromising system security.
There is no patch available for CVE-2002-0461, so users should avoid using affected versions of Internet Explorer.
CVE-2002-0461 affects Internet Explorer versions 5.0.1 through 6.0.
CVE-2002-0461 exploits a vulnerability in JavaScript that results in an application crash due to a loop.
Users can protect themselves by switching to a more secure web browser that does not have this vulnerability.