CVE-2003-0809: High severity Microsoft ie vulnerability
Published Oct 8, 2003
·Updated
Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.
Affected Software
9 affected components
Microsoft ie=6.0-sp1
Microsoft Internet Explorer=5.0.1
Microsoft Internet Explorer=5.0.1-sp1
Microsoft Internet Explorer=5.0.1-sp2
Microsoft Internet Explorer=5.0.1-sp3
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=5.5-sp1
Microsoft Internet Explorer=5.5-sp2
Microsoft Internet Explorer=6.0
Remediation
Patch Available
Event History
Oct 8, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Nov 17, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0809?
CVE-2003-0809 has a critical severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2003-0809?
To fix CVE-2003-0809, users should upgrade to a patched version of Internet Explorer or apply the relevant security updates provided by Microsoft.
3
What versions of Internet Explorer are affected by CVE-2003-0809?
CVE-2003-0809 affects Internet Explorer versions 5.01 through 6.0, including various service packs.
4
What type of attacks can be conducted through CVE-2003-0809?
CVE-2003-0809 allows remote attackers to execute arbitrary code via crafted HTML e-mail messages or web pages.
5
Is CVE-2003-0809 a known vulnerability?
Yes, CVE-2003-0809 is a well-documented vulnerability discovered in 2003.