First published: Tue Dec 31 2002(Updated: )
Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1984 has been classified with a severity rating that indicates it can lead to a denial of service condition.
To mitigate CVE-2002-1984, upgrading to a later version of Microsoft Internet Explorer that is not affected by this vulnerability is recommended.
CVE-2002-1984 affects Microsoft Internet Explorer versions 5.0.1 through 6.0 on Windows 2000 or Windows XP.
CVE-2002-1984 allows remote attackers to cause a denial of service by crafting a specific CLASSID value.
CVE-2002-1984 is largely considered obsolete for modern systems, but users of outdated software may still be vulnerable.