[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2831Date: (C)2005-12-14   (M)2023-12-22


Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015348
SECUNIA-15368
BID-15827
SECUNIA-18064
SECUNIA-18311
OSVDB-21763
ADV-2005-2867
ADV-2005-2909
MS05-054
TA05-347A
VU#959049
http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375420
oval:org.mitre.oval:def:1426
oval:org.mitre.oval:def:1475
oval:org.mitre.oval:def:1520
oval:org.mitre.oval:def:1543
oval:org.mitre.oval:def:1558
oval:org.mitre.oval:def:1597
win-com-activex-execute-code(23453)

OVAL    6
oval:org.mitre.oval:def:1543
oval:org.mitre.oval:def:1520
oval:org.mitre.oval:def:1597
oval:org.mitre.oval:def:1475
...

© SecPod Technologies