CVE-2005-1990

Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.
References
Link Resource
http://secunia.com/advisories/16373/ Patch Vendor Advisory
http://securitytracker.com/id?1014643
http://www.kb.cert.org/vuls/id/959049 US Government Resource
http://www.securityfocus.com/bid/14511
http://www.us-cert.gov/cas/techalerts/TA05-221A.html Patch US Government Resource
http://www.vupen.com/english/advisories/2005/1353
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-038
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100082
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1061
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1221
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1235
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1337
http://secunia.com/advisories/16373/ Patch Vendor Advisory
http://securitytracker.com/id?1014643
http://www.kb.cert.org/vuls/id/959049 US Government Resource
http://www.securityfocus.com/bid/14511
http://www.us-cert.gov/cas/techalerts/TA05-221A.html Patch US Government Resource
http://www.vupen.com/english/advisories/2005/1353
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-038
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100082
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1061
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1221
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1235
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1337
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:58

Type Values Removed Values Added
References () http://secunia.com/advisories/16373/ - Patch, Vendor Advisory () http://secunia.com/advisories/16373/ - Patch, Vendor Advisory
References () http://securitytracker.com/id?1014643 - () http://securitytracker.com/id?1014643 -
References () http://www.kb.cert.org/vuls/id/959049 - US Government Resource () http://www.kb.cert.org/vuls/id/959049 - US Government Resource
References () http://www.securityfocus.com/bid/14511 - () http://www.securityfocus.com/bid/14511 -
References () http://www.us-cert.gov/cas/techalerts/TA05-221A.html - Patch, US Government Resource () http://www.us-cert.gov/cas/techalerts/TA05-221A.html - Patch, US Government Resource
References () http://www.vupen.com/english/advisories/2005/1353 - () http://www.vupen.com/english/advisories/2005/1353 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-038 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-038 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100082 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100082 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1061 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1061 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1221 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1221 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1235 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1235 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1337 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1337 -

Information

Published : 2005-08-10 04:00

Updated : 2024-11-20 23:58


NVD link : CVE-2005-1990

Mitre link : CVE-2005-1990

CVE.ORG link : CVE-2005-1990


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • ie