Open Vulnerability and Assessment Language (OVAL)
Offical Language Release Repository Downloads News — November 5, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:4085 Date: 2005-12-26
Title: IE6,SP2 Channel Definition Format Cross Domain Vulnerability
Description: Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
Version: 2 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-0056
Family: windows
Platform(s): Microsoft Windows XP Product(s): Microsoft Internet Explorer
Definition Synopsis: