Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News July 2, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:1005 Date: 2007-01-13
Title: IE6,SP1 DHTML Method Heap Memory Corruption Vulnerability
Description: Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."
Version: 3 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-0055
Family: windows
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:

OVAL is CVE Compatible