Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News July 2, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:3318 Date: 2007-01-13
Title: IE6,SP1 Channel Definition Format Cross Domain Vulnerability
Description: Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
Version: 3 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-0056
Family: windows
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:

OVAL is CVE Compatible