
Definition Id: oval:org.mitre.oval:def:5316
Oval ID: oval:org.mitre.oval:def:5316
Title: IE v6.0,SP1 (Server 2003) Install Engine Buffer Overflow
Description: Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.
Family: windows Class: vulnerability
Reference(s): CVE-2004-0216
Version: 5
Platform(s): Microsoft Windows Server 2003
Product(s): Microsoft Internet Explorer
Definition Synopsis: