7.5

CVE-2002-1254

Exploit
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ie Version 6.0 Update sp1
Microsoft ≫ Internet Explorer Version 5.5
Microsoft ≫ Internet Explorer Version 5.5 Update sp1
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 53.51% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.ciac.org/ciac/bulletins/n-018.shtml
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066
http://marc.info/?l=bugtraq&m=103530131201191&w=2
http://security.greymagic.com/adv/gm012-ie/
http://www.iss.net/security_center/static/10435.php
http://www.iss.net/security_center/static/10436.php
http://www.iss.net/security_center/static/10437.php
http://www.iss.net/security_center/static/10438.php
http://www.iss.net/security_center/static/10439.php
http://www.securityfocus.com/bid/6028
Patch
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/10432
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A388
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A408