CVE-2002-1254

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
References
Link Resource
http://marc.info/?l=bugtraq&m=103530131201191&w=2
http://security.greymagic.com/adv/gm012-ie/
http://www.ciac.org/ciac/bulletins/n-018.shtml
http://www.iss.net/security_center/static/10435.php
http://www.iss.net/security_center/static/10436.php
http://www.iss.net/security_center/static/10437.php
http://www.iss.net/security_center/static/10438.php
http://www.iss.net/security_center/static/10439.php
http://www.securityfocus.com/bid/6028 Exploit Patch Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066
https://exchange.xforce.ibmcloud.com/vulnerabilities/10432
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A388
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A408
http://marc.info/?l=bugtraq&m=103530131201191&w=2
http://security.greymagic.com/adv/gm012-ie/
http://www.ciac.org/ciac/bulletins/n-018.shtml
http://www.iss.net/security_center/static/10435.php
http://www.iss.net/security_center/static/10436.php
http://www.iss.net/security_center/static/10437.php
http://www.iss.net/security_center/static/10438.php
http://www.iss.net/security_center/static/10439.php
http://www.securityfocus.com/bid/6028 Exploit Patch Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066
https://exchange.xforce.ibmcloud.com/vulnerabilities/10432
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A388
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A408
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:40

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=103530131201191&w=2 - () http://marc.info/?l=bugtraq&m=103530131201191&w=2 -
References () http://security.greymagic.com/adv/gm012-ie/ - () http://security.greymagic.com/adv/gm012-ie/ -
References () http://www.ciac.org/ciac/bulletins/n-018.shtml - () http://www.ciac.org/ciac/bulletins/n-018.shtml -
References () http://www.iss.net/security_center/static/10435.php - () http://www.iss.net/security_center/static/10435.php -
References () http://www.iss.net/security_center/static/10436.php - () http://www.iss.net/security_center/static/10436.php -
References () http://www.iss.net/security_center/static/10437.php - () http://www.iss.net/security_center/static/10437.php -
References () http://www.iss.net/security_center/static/10438.php - () http://www.iss.net/security_center/static/10438.php -
References () http://www.iss.net/security_center/static/10439.php - () http://www.iss.net/security_center/static/10439.php -
References () http://www.securityfocus.com/bid/6028 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/bid/6028 - Exploit, Patch, Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10432 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/10432 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A388 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A388 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A408 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A408 -

Information

Published : 2002-12-11 05:00

Updated : 2024-11-20 23:40


NVD link : CVE-2002-1254

Mitre link : CVE-2002-1254

CVE.ORG link : CVE-2002-1254


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie