First published: Thu Jun 30 2005(Updated: )
Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll). NOTE: the researcher says that the vendor could not reproduce this problem.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =5.1 | |
Microsoft Internet Explorer | =5.2.3 | |
Microsoft Internet Explorer | =6-windows_server_2003_sp1 | |
Internet Explorer | =5.1 | |
Internet Explorer | =5.01-sp4 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-preview | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =6.0 | |
Internet Explorer | =6.0.2900.2180 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2087 has a moderate severity rating due to its potential to cause denial of service and possible remote code execution.
To fix CVE-2005-2087, it is recommended to update to the latest version of Internet Explorer that addresses this vulnerability.
CVE-2005-2087 affects Internet Explorer versions 5.01 SP4 up to 6, including certain versions on Windows and Macintosh operating systems.
CVE-2005-2087 may allow remote attackers to crash the application or potentially execute arbitrary code by exploiting specific embedded CLSIDs on web pages.
While updating is the best protection, users can mitigate risks by disabling scripts and ActiveX controls, which may limit exposure to this vulnerability.