CVE-2000-0767Microsoft Internet Explorer vulnerability

3 documents3 sources
Severity
2.6LOWNVD
EPSS
12.6%
top 6.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 20
Latest updateApr 30

Description

The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.

CVSS vector

AV:N/AC:H/C:P/I:N/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages1 packages

NVDmicrosoft/internet_explorer4 versions+3

Patches

🔴Vulnerability Details

1
GHSA
GHSA-7j3m-5478-cr36: The ActiveX control for invoking a scriptlet in Internet Explorer 42022-04-30

💥Exploits & PoCs

1
Exploit-DB
IBM AIX 4.2.1 / Sun Solaris 7.0 - LC_MESSAGES libc Buffer Overflow (4)1999-05-22
CVE-2000-0767 — Microsoft vulnerability | cvebase