CVE-2003-0815
Summary
| CVE | CVE-2003-0815 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-02-03 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Ie | 6.0 | sp1 | All | All |
| Application | Microsoft | Internet Explorer | 5.0.1 | All | All | All |
| Application | Microsoft | Internet Explorer | 5.0.1 | sp1 | All | All |
| Application | Microsoft | Internet Explorer | 5.0.1 | sp2 | All | All |
| Application | Microsoft | Internet Explorer | 5.0.1 | sp3 | All | All |
| Application | Microsoft | Internet Explorer | 5.5 | All | All | All |
| Application | Microsoft | Internet Explorer | 5.5 | sp1 | All | All |
| Application | Microsoft | Internet Explorer | 5.5 | sp2 | All | All |
| Application | Microsoft | Internet Explorer | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Internet Explorer Function Pointer Override Cross-Domain Access Violation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Microsoft Security Bulletin MS03-048 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.osvdb.org/7889 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| 'MSIE->Findeath: break caller-based authorization' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Secunia - Advisories - Microsoft Internet Explorer Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus Bugtraq: MSIE->LinkillerSaveRef:another caller-based authorization | af854a3a-2127-422b-91ae-364da2661108 | www.derkeiler.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| 'MSIE->LinkillerJPU:another caller-based authorization(is broken).' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Microsoft Internet Explorer Various Cross-Domain Flaws Permit Remote Scripting in Arbitrary Domains - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.ciac.org/ciac/bulletins/o-021.shtml | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| safecenter.net is for sale | af854a3a-2127-422b-91ae-364da2661108 | www.safecenter.net | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.osvdb.org/7888 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| safecenter.net is for sale | af854a3a-2127-422b-91ae-364da2661108 | www.safecenter.net | |
| safecenter.net is for sale | af854a3a-2127-422b-91ae-364da2661108 | www.safecenter.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.