{"api_version":"1","generated_at":"2026-07-23T04:31:34+00:00","cve":"CVE-2000-0982","urls":{"html":"https://cve.report/CVE-2000-0982","api":"https://cve.report/api/cve/CVE-2000-0982.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2000-0982","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2000-0982"},"summary":{"title":"CVE-2000-0982","description":"Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the \"Cached Web Credentials\" vulnerability.","state":"PUBLISHED","assigner":"mitre","published_at":"2000-12-19 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt","name":"http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-076","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-076","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS00-076 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/1793","name":"http://www.securityfocus.com/bid/1793","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Microsoft Internet Explorer Cached Web Credentials Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5367","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2000-0982","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2000-0982","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2000","cve_id":"982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2000","cve_id":"982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"4.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2000","cve_id":"982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2000","cve_id":"982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2000","cve_id":"982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T05:37:32.016Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1793","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/1793"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt"},{"name":"ie-cache-info(5367)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5367"},{"name":"MS00-076","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-076"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2000-10-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the \"Cached Web Credentials\" vulnerability."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-11-02T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1793","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/1793"},{"tags":["x_refsource_MISC"],"url":"http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt"},{"name":"ie-cache-info(5367)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5367"},{"name":"MS00-076","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-076"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2000-0982","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the \"Cached Web Credentials\" vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1793","refsource":"BID","url":"http://www.securityfocus.com/bid/1793"},{"name":"http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt","refsource":"MISC","url":"http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt"},{"name":"ie-cache-info(5367)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5367"},{"name":"MS00-076","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-076"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2000-0982","datePublished":"2001-01-22T05:00:00.000Z","dateReserved":"2000-11-24T00:00:00.000Z","dateUpdated":"2024-08-08T05:37:32.016Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2000-12-19 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*","matchCriteriaId":"A5B815D9-BC21-4A17-AF00-B8AD181027D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:*","matchCriteriaId":"42502347-DD40-4F8C-9861-C0A88A3F8608"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:4.1:*:*:*:*:*:*:*","matchCriteriaId":"44FF4E47-AD75-42C7-BB84-42BBA46A58B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*","matchCriteriaId":"E6B8985B-B927-4928-B1DB-18E29F796992"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*","matchCriteriaId":"6219D36E-9E2C-4DC7-8FD5-FAD144A333F6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2000","CveId":"982","Ordinal":"1","Title":"CVE-2000-0982","CVE":"CVE-2000-0982","Year":"2000"},"notes":[{"CveYear":"2000","CveId":"982","Ordinal":"1","NoteData":"Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the \"Cached Web Credentials\" vulnerability.","Type":"Description","Title":"CVE-2000-0982"},{"CveYear":"2000","CveId":"982","Ordinal":"2","NoteData":"2001-01-22","Type":"Other","Title":"Published"},{"CveYear":"2000","CveId":"982","Ordinal":"3","NoteData":"2005-11-02","Type":"Other","Title":"Modified"}]}}}