| Vulnerability Name: | CVE-2000-0464 (CCN-4502) | ||||||||
| Assigned: | 2000-05-17 | ||||||||
| Published: | 2000-05-17 | ||||||||
| Updated: | 2021-07-23 | ||||||||
| Summary: | Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability. | ||||||||
| CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2000-0464 Source: CCN Type: CIAC Information Bulletin K-044 Microsoft: Vulnerabilities in Internet Explorer Source: CCN Type: Microsoft Security Bulletin MS00-033 Patch Available for "Frame Domain Verification", "Unauthorized Cookie Access", and "Malformed Component Attribute" Vulnerabilities Source: MSKB Type: UNKNOWN Q261257 Source: CCN Type: OSVDB ID: 1341 Microsoft IE ActiveX Combined Component Attributes Source: BID Type: UNKNOWN 1223 Source: CCN Type: BID-1223 MS IE ActiveX Combined Component Attributes Vulnerability Source: MS Type: UNKNOWN MS00-033 Source: XF Type: UNKNOWN ie-malformed-component-attribute(4502) Source: CCN Type: Microsoft Knowledge Base Article 261257 Malformed Component Attribute Issue in Internet Explorer | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||