CVE-1999-1087
published 1999-12-31CVE-1999-1087: Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local…
PriorityP420high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.28%
92.8th percentile
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Internet Explorer 4.0/4.0.1 Dotless IP Address URL privileges management (MS98-016 / XFDB-2209)
vuldb·2026-04-20·CVSS 7.5
CVE-1999-1087 [HIGH] Microsoft Internet Explorer 4.0/4.0.1 Dotless IP Address URL privileges management (MS98-016 / XFDB-2209)
A vulnerability categorized as critical has been discovered in Microsoft Internet Explorer 4.0/4.0.1. This vulnerability affects unknown code of the component Dotless IP Address Handler. Such manipulation as part of URL leads to improper privilege management.
This vulnerability is listed as CVE-1999-1087. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
GHSA-9rv3-rxw8-xr7c: Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Loca
ghsa_unreviewed·2022-04-30
CVE-1999-1087 [HIGH] GHSA-9rv3-rxw8-xr7c: Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Loca
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://support.microsoft.com/support/kb/articles/q168/6/17.asphttp://www.microsoft.com/Windows/Ie/security/dotless.asphttp://www.osvdb.org/7828https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-016https://exchange.xforce.ibmcloud.com/vulnerabilities/2209http://support.microsoft.com/support/kb/articles/q168/6/17.asphttp://www.microsoft.com/Windows/Ie/security/dotless.asphttp://www.osvdb.org/7828https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-016https://exchange.xforce.ibmcloud.com/vulnerabilities/2209
1999-12-31
Published