CVE-2002-0461: Medium severity Microsoft Internet Explorer vulnerability
Published Jun 11, 2002
·Updated
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.
Affected Software
7 affected components
Microsoft Internet Explorer=5.5-sp2
Microsoft Internet Explorer=5.0.1
Microsoft Internet Explorer=5.0.1-sp2
Microsoft Internet Explorer=5.0.1-sp1
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=5.5-sp1
Microsoft Internet Explorer=6.0
Remediation
Patch Available
Event History
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0461?
CVE-2002-0461 has a low severity rating as it causes a denial of service without compromising system security.
2
How do I fix CVE-2002-0461?
There is no patch available for CVE-2002-0461, so users should avoid using affected versions of Internet Explorer.
3
Which versions of Internet Explorer are affected by CVE-2002-0461?
CVE-2002-0461 affects Internet Explorer versions 5.0.1 through 6.0.
4
What type of attack does CVE-2002-0461 exploit?
CVE-2002-0461 exploits a vulnerability in JavaScript that results in an application crash due to a loop.
5
What can users do to protect against CVE-2002-0461?
Users can protect themselves by switching to a more secure web browser that does not have this vulnerability.