CVE-1999-0967
published 1997-11-01CVE-1999-0967: Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
PriorityP425critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.96%
93.4th percentile
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Internet Explorer 4.0 HTML Library res Link memory corruption (XFDB-3837 / SBV-2874)
vuldb·2026-04-17·CVSS 10.0
CVE-1999-0967 [CRITICAL] Microsoft Internet Explorer 4.0 HTML Library res Link memory corruption (XFDB-3837 / SBV-2874)
A vulnerability has been found in Microsoft Internet Explorer 4.0 and classified as critical. This vulnerability affects unknown code of the component HTML Library. This manipulation as part of res Link causes memory corruption.
This vulnerability is tracked as CVE-1999-0967. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-2wpq-5932-m8cw: Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol
ghsa_unreviewed·2022-04-30
CVE-1999-0967 [HIGH] GHSA-2wpq-5932-m8cw: Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1997-11-01
Published