Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2001-0002 | First vendor Publication | 2001-07-21 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0002 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:920 | |||
Oval ID: | oval:org.mitre.oval:def:920 | ||
Title: | IE Cached Content Command Execution Vulnerability | ||
Description: | Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2001-0002 | Version: | 3 |
Platform(s): | Microsoft Windows 98 Microsoft Windows NT Microsoft Windows 2000 | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : IE 5.01 5.5 6.0 Cumulative patch (890923) File : nvt/smb_nt_ms02-005.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
7823 | Microsoft IE Cached Content .chm Arbitrary Program Execution Microsoft Internet Explorer contains a flaw that may allow a remote attacker to execute arbitrary commands. Internet Explorer allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows Media Player 7+ ActiveX object access RuleID : 4156 - Revision : 14 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Internet Explorer htmlfile ActiveX object access attempt RuleID : 4155 - Revision : 20 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Internet Explorer htmlfile ActiveX object access attempt RuleID : 28272 - Revision : 7 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2003-03-12 | Name : The remote host is vulnerable to privilege escalation. File : smb_nt_ms02-001.nasl - Type : ACT_GATHER_INFO |
2002-02-13 | Name : Arbitrary code can be executed on the remote host through the web client. File : smb_nt_ms02-005.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:24:20 |
|
2024-11-28 12:04:17 |
|
2021-07-24 09:24:34 |
|
2021-07-23 17:24:42 |
|
2021-07-23 12:01:19 |
|
2021-05-04 12:01:15 |
|
2021-04-22 01:01:27 |
|
2020-05-23 01:35:25 |
|
2020-05-23 00:14:31 |
|
2018-10-13 00:22:23 |
|
2018-05-03 09:19:24 |
|
2016-06-28 14:54:38 |
|
2016-04-27 09:20:40 |
|
2016-04-26 11:47:44 |
|
2013-08-31 13:20:04 |
|
2013-05-11 12:02:36 |
|