CVE-2006-5805
published 2006-11-08CVE-2006-5805: Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to…
PriorityP415medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
5.86%
92.4th percentile
Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/invalidcert.htm with the target site as an argument, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Internet Explorer 7.0 Address Bar invalidcert.htm (ID 1017165)
vuldb·2026-04-27·CVSS 5.0
CVE-2006-5805 [MEDIUM] Microsoft Internet Explorer 7.0 Address Bar invalidcert.htm (ID 1017165)
A vulnerability was found in Microsoft Internet Explorer 7.0. It has been rated as problematic. Affected by this vulnerability is an unknown functionality in the library res://ieframe.dll/invalidcert.htm of the component Address Bar. This manipulation causes an unknown weakness.
This vulnerability is tracked as CVE-2006-5805. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
GHSA-r382-7625-8wwh: Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ief
ghsa_unreviewed·2022-05-01
CVE-2006-5805 [MEDIUM] GHSA-r382-7625-8wwh: Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ief
Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/invalidcert.htm with the target site as an argument, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid.
GHSA
GHSA-5r9w-7j85-fv72: Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res:/
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-5913 [MEDIUM] GHSA-5r9w-7j85-fv72: Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res:/
Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/sslnavcancel.htm with the target site in the anchor identifier, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid, or (2) trigger a "The webpage no longer exists" report via a link to res://ieframe.dll/http_410.htm, a variant of CVE-2006-5805.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ingehenriksen.blogspot.com/2006/11/ie7-website-security-certificate.htmlhttp://securitytracker.com/id?1017165http://www.securityfocus.com/archive/1/450722/100/0/threadedhttp://ingehenriksen.blogspot.com/2006/11/ie7-website-security-certificate.htmlhttp://securitytracker.com/id?1017165http://www.securityfocus.com/archive/1/450722/100/0/threaded
2006-11-08
Published