CVE-2002-0077 describes a critical vulnerability in Microsoft Internet Explorer versions 5.01, 5.5, and 6.0, where objects invoked via the codebase property on an HTML page were incorrectly treated as part of the Local Computer zone. This flaw allowed remote attackers to execute local system executables, such as the popup object, leading to potential compromise of the affected system. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and could result in partial confidentiality, integrity, and availability impacts. While no active exploitation, public exploit code, or significant community discussion has been identified, the vulnerability's age and the affected product's end-of-life status likely contribute to its inactive status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.1CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.