CVE-2003-0532

Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html - Exploit, Vendor Advisory () http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html - Exploit, Vendor Advisory
References () http://marc.info/?l=bugtraq&m=106149026621753&w=2 - () http://marc.info/?l=bugtraq&m=106149026621753&w=2 -
References () http://www.eeye.com/html/Research/Advisories/AD20030820.html - () http://www.eeye.com/html/Research/Advisories/AD20030820.html -
References () http://www.kb.cert.org/vuls/id/865940 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/865940 - Third Party Advisory, US Government Resource
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032 -

Information

Published : 2003-08-27 04:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0532

Mitre link : CVE-2003-0532

CVE.ORG link : CVE-2003-0532


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie