CVE-2005-3312
Summary
| CVE | CVE-2005-3312 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-10-26 10:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on the link, even though the web server response and file extension indicate that it should be treated as a different file type. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecuriTeam.com ™ - Microsoft Internet Explorer 6.0 Embedded Content Cross Site Scripting (GIF) | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | Vendor Advisory |
| computec.ch • 1997 - 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.computec.ch | Exploit |
| 'phpBB 2.0.17 (and other BB systems as well) Cookie disclosure' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| scip AG [Security - Consulting - Information - Process] | af854a3a-2127-422b-91ae-364da2661108 | www.scip.ch | Exploit, Vendor Advisory |
| Microsoft Internet Explorer 6.0 embedded content cross site scripting - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.