CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2004-0216

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1200%
EPSS Percentile33.32th
Published2004年11月3日
Last Modified2026年4月16日

Vulnerability Description

Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.

Affected Platforms (CPE)

📦
Microsoft

Ie

= 6
📦
Microsoft

Internet Explorer

= 5.01
📦
Microsoft

Internet Explorer

= 5.5

References & Advisories

相關漏洞威脅