{"api_version":"1","generated_at":"2026-07-23T03:24:22+00:00","cve":"CVE-2001-0664","urls":{"html":"https://cve.report/CVE-2001-0664","api":"https://cve.report/api/cve/CVE-2001-0664.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0664","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0664"},"summary":{"title":"CVE-2001-0664","description":"Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the \"Zone Spoofing vulnerability.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2001-10-30 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7258","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7258","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://morph3us.org/blog/?p=31","name":"http://morph3us.org/blog/?p=31","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Beat me, break me.  » Blog Archive   » Dotless IP addresses and URL Obfuscation","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.osvdb.org/1971","name":"http://www.osvdb.org/1971","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"http://marc.info/?l=bugtraq&m=100281551611595&w=2","name":"http://marc.info/?l=bugtraq&m=100281551611595&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS01-051 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/3420","name":"http://www.securityfocus.com/bid/3420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Zone Spoofing Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0664","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0664","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"664","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"664","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:30:06.020Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://morph3us.org/blog/?p=31"},{"name":"20011011 Serious security Flaw in Microsoft Internet Explorer - Zone Spoofing","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=100281551611595&w=2"},{"name":"1971","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/1971"},{"name":"ie-incorrect-security-zone(7258)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7258"},{"name":"MS01-051","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051"},{"name":"3420","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3420"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-10-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the \"Zone Spoofing vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-09-11T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://morph3us.org/blog/?p=31"},{"name":"20011011 Serious security Flaw in Microsoft Internet Explorer - Zone Spoofing","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=100281551611595&w=2"},{"name":"1971","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/1971"},{"name":"ie-incorrect-security-zone(7258)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7258"},{"name":"MS01-051","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051"},{"name":"3420","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3420"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0664","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the \"Zone Spoofing vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://morph3us.org/blog/?p=31","refsource":"MISC","url":"http://morph3us.org/blog/?p=31"},{"name":"20011011 Serious security Flaw in Microsoft Internet Explorer - Zone Spoofing","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=100281551611595&w=2"},{"name":"1971","refsource":"OSVDB","url":"http://www.osvdb.org/1971"},{"name":"ie-incorrect-security-zone(7258)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7258"},{"name":"MS01-051","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051"},{"name":"3420","refsource":"BID","url":"http://www.securityfocus.com/bid/3420"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0664","datePublished":"2002-03-09T05:00:00.000Z","dateReserved":"2001-08-15T00:00:00.000Z","dateUpdated":"2024-08-08T04:30:06.020Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-10-30 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*","matchCriteriaId":"6219D36E-9E2C-4DC7-8FD5-FAD144A333F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*","matchCriteriaId":"40F8042F-C621-45AE-9F8C-70469579643A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"664","Ordinal":"1","Title":"CVE-2001-0664","CVE":"CVE-2001-0664","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"664","Ordinal":"1","NoteData":"Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the \"Zone Spoofing vulnerability.\"","Type":"Description","Title":"CVE-2001-0664"},{"CveYear":"2001","CveId":"664","Ordinal":"2","NoteData":"2002-03-09","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"664","Ordinal":"3","NoteData":"2006-09-10","Type":"Other","Title":"Modified"}]}}}