VulnerabilityModified
CVE-2001-0338
Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation…
MEDIUM 5.1EPSS 5.32%
Does this matter?
Lower severity and a low EPSS score (5.32%). Track it; it rarely justifies an emergency change on its own.
Description
Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 5.32% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://www.ciac.org/ciac/bulletins/l-087.shtml
- http://www.securityfocus.com/bid/2735
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6555
- http://www.ciac.org/ciac/bulletins/l-087.shtml
- http://www.securityfocus.com/bid/2735
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6555
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.