CVE-2005-0056

Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
References
Link Resource
http://securitytracker.com/id?1013126
http://www.kb.cert.org/vuls/id/823971 Patch US Government Resource
http://www.securityfocus.com/bid/12427 Exploit Patch
http://www.us-cert.gov/cas/techalerts/TA05-039A.html Patch US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-014
https://exchange.xforce.ibmcloud.com/vulnerabilities/19137
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2385
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2817
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3318
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4085
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4947
http://securitytracker.com/id?1013126
http://www.kb.cert.org/vuls/id/823971 Patch US Government Resource
http://www.securityfocus.com/bid/12427 Exploit Patch
http://www.us-cert.gov/cas/techalerts/TA05-039A.html Patch US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-014
https://exchange.xforce.ibmcloud.com/vulnerabilities/19137
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2385
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2817
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3318
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4085
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4947
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () http://securitytracker.com/id?1013126 - () http://securitytracker.com/id?1013126 -
References () http://www.kb.cert.org/vuls/id/823971 - Patch, US Government Resource () http://www.kb.cert.org/vuls/id/823971 - Patch, US Government Resource
References () http://www.securityfocus.com/bid/12427 - Exploit, Patch () http://www.securityfocus.com/bid/12427 - Exploit, Patch
References () http://www.us-cert.gov/cas/techalerts/TA05-039A.html - Patch, US Government Resource () http://www.us-cert.gov/cas/techalerts/TA05-039A.html - Patch, US Government Resource
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-014 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-014 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/19137 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/19137 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2385 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2385 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2817 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2817 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3318 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3318 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4085 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4085 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4947 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4947 -

Information

Published : 2005-05-02 04:00

Updated : 2024-11-20 23:54


NVD link : CVE-2005-0056

Mitre link : CVE-2005-0056

CVE.ORG link : CVE-2005-0056


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie