{"api_version":"1","generated_at":"2026-07-23T05:32:14+00:00","cve":"CVE-2001-0002","urls":{"html":"https://cve.report/CVE-2001-0002","api":"https://cve.report/api/cve/CVE-2001-0002.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0002","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0002"},"summary":{"title":"CVE-2001-0002","description":"Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-07-21 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS01-015 - Important | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/7823","name":"http://www.osvdb.org/7823","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5567","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5567","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/2456","name":"http://www.securityfocus.com/bid/2456","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft IE Temporary Internet Files Folder Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.guninski.com/chmtempmain.html","name":"http://www.guninski.com/chmtempmain.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Wait 60 seconds.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0002","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0002","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"2","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"2","vulnerable":"1","versionEndIncluding":"5.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"2","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"windows_script_host","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"2","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"windows_script_host","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:06:54.599Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"oval:org.mitre.oval:def:920","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920"},{"name":"7823","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/7823"},{"name":"MS01-015","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015"},{"name":"ie-chm-execute-files(5567)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5567"},{"name":"2456","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/2456"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.guninski.com/chmtempmain.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-03-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2004-09-02T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"oval:org.mitre.oval:def:920","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920"},{"name":"7823","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/7823"},{"name":"MS01-015","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015"},{"name":"ie-chm-execute-files(5567)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5567"},{"name":"2456","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/2456"},{"tags":["x_refsource_MISC"],"url":"http://www.guninski.com/chmtempmain.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0002","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"oval:org.mitre.oval:def:920","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920"},{"name":"7823","refsource":"OSVDB","url":"http://www.osvdb.org/7823"},{"name":"MS01-015","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015"},{"name":"ie-chm-execute-files(5567)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5567"},{"name":"2456","refsource":"BID","url":"http://www.securityfocus.com/bid/2456"},{"name":"http://www.guninski.com/chmtempmain.html","refsource":"MISC","url":"http://www.guninski.com/chmtempmain.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0002","datePublished":"2001-05-07T04:00:00.000Z","dateReserved":"2001-01-04T00:00:00.000Z","dateUpdated":"2024-08-08T04:06:54.599Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-07-21 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*","versionEndIncluding":"5.5","matchCriteriaId":"7BDFCFCB-6E90-4F29-9852-A3099DF05843"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*","matchCriteriaId":"6219D36E-9E2C-4DC7-8FD5-FAD144A333F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:windows_script_host:5.1:*:*:*:*:*:*:*","matchCriteriaId":"D774C5CD-AD4A-42F9-B624-968A0C1DDE2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:windows_script_host:5.5:*:*:*:*:*:*:*","matchCriteriaId":"CF47D9C0-6521-427A-A1EB-3BFA2BD37733"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"2","Ordinal":"1","Title":"CVE-2001-0002","CVE":"CVE-2001-0002","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"2","Ordinal":"1","NoteData":"Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.","Type":"Description","Title":"CVE-2001-0002"},{"CveYear":"2001","CveId":"2","Ordinal":"2","NoteData":"2001-05-07","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"2","Ordinal":"3","NoteData":"2004-09-02","Type":"Other","Title":"Modified"}]}}}