VulnerabilityModified
CVE-2004-1173
Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog.
HIGH 7.5EPSS 11.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 11.72% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110271114525795&w=2
- http://marc.info/?l=ntbugtraq&m=110271016129952&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18444
- http://marc.info/?l=bugtraq&m=110271114525795&w=2
- http://marc.info/?l=ntbugtraq&m=110271016129952&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18444
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.