First published: Mon May 02 2005(Updated: )
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
microsoft ie | =6.0-sp1 | |
microsoft ie | =6.0-sp2 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp3 | |
Internet Explorer | =5.0.1-sp4 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =6.0 | |
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows 2003 Server | =enterprise_64-bit | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 98 | =gold | |
Microsoft Windows 98SE | ||
Microsoft Windows Me | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Internet Explorer | =6.0-sp1 | |
Microsoft Internet Explorer | =6.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0053 is rated as a critical severity vulnerability due to its ability to allow remote attackers to execute arbitrary code.
To fix CVE-2005-0053, users should upgrade to the latest version of Internet Explorer or apply the relevant security updates provided by Microsoft.
CVE-2005-0053 affects Internet Explorer versions 5.01, 5.5, and 6.x, including their service packs.
CVE-2005-0053 exploits the drag and drop functionality in Internet Explorer to execute arbitrary code.
Yes, CVE-2005-0053 can be exploited remotely without the user's knowledge via malicious web pages.