[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2829Date: (C)2005-12-14   (M)2023-12-22


Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.1
Exploit Score: 4.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015349
SECUNIA-15368
BID-15823
SECUNIA-18064
SECUNIA-18311
http://www.securityfocus.com/archive/1/419395/100/0/threaded
http://marc.info/?l=full-disclosure&m=113450519906463&w=2
SREASON-254
ADV-2005-2867
ADV-2005-2909
MS05-054
http://secunia.com/secunia_research/2005-21/advisory
http://secunia.com/secunia_research/2005-7/advisory/
http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375420
ie-dialog-box-code-execution(23448)
oval:org.mitre.oval:def:1209
oval:org.mitre.oval:def:1340
oval:org.mitre.oval:def:1458
oval:org.mitre.oval:def:1490
oval:org.mitre.oval:def:1505
oval:org.mitre.oval:def:1507

OVAL    6
oval:org.mitre.oval:def:1507
oval:org.mitre.oval:def:1490
oval:org.mitre.oval:def:1209
oval:org.mitre.oval:def:1505
...

© SecPod Technologies