CVE-2005-2127
Summary
| CVE | CVE-2005-2127 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-08-19 04:00:00 UTC |
| Updated | 2018-10-19 15:32:00 UTC |
| Description | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability." |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ati | Catalyst Driver | All | All | All | All |
| Application | Ati | Catalyst Driver | All | All | All | All |
| Application | Microsoft | .net Framework | 1.1 | All | All | All |
| Application | Microsoft | .net Framework | 1.1 | sp1 | All | All |
| Application | Microsoft | .net Framework | 1.1 | sp2 | All | All |
| Application | Microsoft | .net Framework | 1.1 | sp3 | All | All |
| Application | Microsoft | .net Framework | 1.1 | All | All | All |
| Application | Microsoft | .net Framework | 1.1 | sp1 | All | All |
| Application | Microsoft | .net Framework | 1.1 | sp2 | All | All |
| Application | Microsoft | .net Framework | 1.1 | sp3 | All | All |
| Application | Microsoft | Office | All | All | All | All |
| Application | Microsoft | Office | 2000 | All | All | All |
| Application | Microsoft | Office | 2000 | All | All | ja |
| Application | Microsoft | Office | 2000 | All | All | ko |
| Application | Microsoft | Office | 2000 | All | All | zh |
| Application | Microsoft | Office | 2000 | sp1 | All | All |
| Application | Microsoft | Office | 2000 | sp2 | All | All |
| Application | Microsoft | Office | 2000 | sp3 | All | All |
| Application | Microsoft | Office | xp | sp1 | All | All |
| Application | Microsoft | Office | xp | sp2 | All | All |
| Application | Microsoft | Office | xp | sp3 | All | All |
| Application | Microsoft | Office | All | All | All | All |
| Application | Microsoft | Office | 2000 | All | All | All |
| Application | Microsoft | Office | 2000 | All | All | ja |
| Application | Microsoft | Office | 2000 | All | All | ko |
| Application | Microsoft | Office | 2000 | All | All | zh |
| Application | Microsoft | Office | 2000 | sp1 | All | All |
| Application | Microsoft | Office | 2000 | sp2 | All | All |
| Application | Microsoft | Office | 2000 | sp3 | All | All |
| Application | Microsoft | Office | xp | sp1 | All | All |
| Application | Microsoft | Office | xp | sp2 | All | All |
| Application | Microsoft | Office | xp | sp3 | All | All |
| Application | Microsoft | Project | 2000 | All | All | All |
| Application | Microsoft | Project | 2002 | All | All | All |
| Application | Microsoft | Project | 2002 | sp1 | All | All |
| Application | Microsoft | Project | 2003 | All | All | All |
| Application | Microsoft | Project | 2003 | sp1 | All | All |
| Application | Microsoft | Project | 98 | All | All | All |
| Application | Microsoft | Project | 2000 | All | All | All |
| Application | Microsoft | Project | 2002 | All | All | All |
| Application | Microsoft | Project | 2002 | sp1 | All | All |
| Application | Microsoft | Project | 2003 | All | All | All |
| Application | Microsoft | Project | 2003 | sp1 | All | All |
| Application | Microsoft | Project | 98 | All | All | All |
| Application | Microsoft | Visio | 2000 | sr1 | All | All |
| Application | Microsoft | Visio | 2002 | All | All | All |
| Application | Microsoft | Visio | 2002 | All | All | All |
| Application | Microsoft | Visio | 2002 | sp1 | All | All |
| Application | Microsoft | Visio | 2002 | sp2 | All | All |
| Application | Microsoft | Visio | 2002 | sp2 | All | All |
| Application | Microsoft | Visio | 2002 | sp2 | All | All |
| Application | Microsoft | Visio | 2003 | All | All | All |
| Application | Microsoft | Visio | 2003 | All | All | All |
| Application | Microsoft | Visio | 2003 | All | All | All |
| Application | Microsoft | Visio | 2003 | sp1 | All | All |
| Application | Microsoft | Visio | 2000 | sr1 | All | All |
| Application | Microsoft | Visio | 2002 | All | All | All |
| Application | Microsoft | Visio | 2002 | All | All | All |
| Application | Microsoft | Visio | 2002 | sp1 | All | All |
| Application | Microsoft | Visio | 2002 | sp2 | All | All |
| Application | Microsoft | Visio | 2002 | sp2 | All | All |
| Application | Microsoft | Visio | 2002 | sp2 | All | All |
| Application | Microsoft | Visio | 2003 | All | All | All |
| Application | Microsoft | Visio | 2003 | All | All | All |
| Application | Microsoft | Visio | 2003 | All | All | All |
| Application | Microsoft | Visio | 2003 | sp1 | All | All |
| Application | Microsoft | Visual Studio .net | 2002 | gold | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | All | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | gold | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | 2002 | gold | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | All | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | gold | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
| Application | Microsoft | Visual Studio .net | gold | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Broken Link |
| Secunia - Advisories - Microsoft Windows COM Object Instantiation Memory Corruption Vulnerability | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Microsoft Security Bulletin MS05-052 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System | MISC | isc.sans.org | Third Party Advisory |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry |
| Your request has been blocked. This could be due to several reasons. | MISC | www.microsoft.com | Mitigation, Patch, Vendor Advisory |
| Secunia - Advisories - Avaya Various Products Multiple Vulnerabilities | SECUNIA | secunia.com | Permissions Required, Third Party Advisory |
| SecurityReason | SREASON | securityreason.com | Third Party Advisory |
| SecurityTracker.com Archives - Microsoft 'msdds.dll' COM Object Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| US-CERT Technical Cyber Security Alert TA06-220A -- Microsoft Products Contain Multiple Vulnerabilities | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Secunia - Advisories - Nortel CallPilot Multiple Vulnerabilities | SECUNIA | secunia.com | Permissions Required, Third Party Advisory |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| support.avaya.com/elmodocs2/security/ASA-2005-214.pdf | CONFIRM | support.avaya.com | Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA05-347A -- Microsoft Internet Explorer Vulnerabilities | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Microsoft Visual Studio .NET msdds.dll Remote Code Execution Vulnerability | BID | www.securityfocus.com | Exploit, Patch, Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry |
| Secunia - Advisories - Nortel Centrex IP Client Manager Multiple Vulnerabilities | SECUNIA | secunia.com | Permissions Required, Third Party Advisory |
| US-CERT Vulnerability Note VU#898241 | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| US-CERT Technical Cyber Security Alert TA05-284A -- Microsoft Windows, Internet Explorer, and Exchange Server Vulnerabilities | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| US-CERT Vulnerability Note VU#959049 | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| US-CERT Vulnerability Note VU#740372 | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.