Multiple Microsoft Internet Explorer...

- AV AC AU C I A
发布: 2002-08-22
修订: 2025-04-13

Microsoft has released a security bulletin describing multiple vulnerabilities in Internet Explorer 5.01, 5.5 and 6.0. The first issue is a buffer overflow in the Gopher protocol handler. This vulnerability was previously alerted on and is described in further detail in Bugtraq ID 4930 "Multiple Microsoft Product Gopher Client Buffer Overflow Vulnerability". The second issue is described to be a buffer overflow in an ActiveX component used to display specially formatted text. This issue in the Legacy Text Formatting component may enable a remote attacker to execute code on a client system with the privileges of the user running the affected client. The vulnerable component is reportedly not installed by default in current versions of Internet Explorer and was removed from the Microsoft website when the vendor first learned of the issue. The third issue reportedly allows a remote attacker to exploit the browser to read XML data that is located in a known location. The source of the...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息