VulnerabilityModified
CVE-2003-0113
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.
HIGH 7.5EPSS 39.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 39.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 39.37% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie · microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=105138417416900&w=2
- http://marc.info/?l=bugtraq&m=105718285107246&w=2
- http://www.kb.cert.org/vuls/id/169753US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A926
- http://marc.info/?l=bugtraq&m=105138417416900&w=2
- http://marc.info/?l=bugtraq&m=105718285107246&w=2
- http://www.kb.cert.org/vuls/id/169753US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A926
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.