CVE-2005-2127
Published Aug 19, 2005
Last updated 6 years ago
Overview
- Description
- Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."
- Source
- secure@microsoft.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ati:catalyst_driver:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62E822DD-6123-4CD8-9FE4-BC8A91D94F80" }, { "criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A927C9E-5CCC-4FC1-AE63-24B96A5FC51A" }, { "criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BF6AE15-EAC3-4100-A742-211026C79CCC" }, { "criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2804E22-FFF4-4301-8958-16B32CE5ECD1" }, { "criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B33B1B47-EEA0-4B1F-AC03-CAB56AB42DC7" }, { "criteria": "cpe:2.3:a:microsoft:office:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49AD45BF-8A91-4C87-AF15-D38D8468A4C5" }, { "criteria": "cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9A82D13-513C-46FA-AF51-0582233E230A" }, { "criteria": "cpe:2.3:a:microsoft:office:2000:*:*:ja:*:*:*:*", "vulnerable": true, "matchCriteriaId": "757EC6C1-F5E2-45CD-9F7F-7760ECEDC842" }, { "criteria": "cpe:2.3:a:microsoft:office:2000:*:*:ko:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59B1B68C-86F1-4FA4-9F82-3E8761ED1E74" }, { "criteria": "cpe:2.3:a:microsoft:office:2000:*:*:zh:*:*:*:*", "vulnerable": true, "matchCriteriaId": "716DDA05-D094-4837-852C-0511CDDD5ABC" }, { "criteria": "cpe:2.3:a:microsoft:office:2000:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C54DDAF-8D7F-4A7D-9186-6048D4C850B2" }, { "criteria": "cpe:2.3:a:microsoft:office:2000:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67388076-420D-4327-A436-329177EA6F42" }, { "criteria": "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4891122F-AD7F-45E6-98C6-833227916F6B" }, { "criteria": "cpe:2.3:a:microsoft:office:xp:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5AB85A3C-EFA3-485D-84C5-7976718AEAE0" }, { "criteria": "cpe:2.3:a:microsoft:office:xp:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D02D769-061D-44A5-B019-F4E653DF615A" }, { "criteria": "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79BA1175-7F02-4435-AEA6-1BA8AADEB7EF" }, { "criteria": "cpe:2.3:a:microsoft:project:98:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77BFDC2A-4AE1-4FC8-ABA7-0400D46EA587" }, { "criteria": "cpe:2.3:a:microsoft:project:2000:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F09162C-01F0-4056-94D3-995713F92AE9" }, { "criteria": "cpe:2.3:a:microsoft:project:2002:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AE2D3E0-49E4-410E-B63A-753BDE8995BB" }, { "criteria": "cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B14AE8E-1BFF-4458-87CC-357957F18F8A" }, { "criteria": "cpe:2.3:a:microsoft:project:2003:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34EFAEFE-2BDE-4111-91F5-E9F75ADFA920" }, { "criteria": "cpe:2.3:a:microsoft:project:2003:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC1DA2B8-C41B-4EB9-A58F-E4E63F695A55" }, { "criteria": "cpe:2.3:a:microsoft:visio:2000:sr1:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "B4EC96E0-8D7C-4C72-8F04-97B0B675306E" }, { "criteria": "cpe:2.3:a:microsoft:visio:2002:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E24DF34-F4A8-4C28-9593-F019FE3E3BA2" }, { "criteria": "cpe:2.3:a:microsoft:visio:2002:*:*:*:professional:*:*:*", "vulnerable": true, "matchCriteriaId": "FF41DACB-D707-4ED3-BA2E-2EEABC17FC4D" }, { "criteria": "cpe:2.3:a:microsoft:visio:2002:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70D447B9-4604-447C-88FC-F5DC8F77603C" }, { "criteria": "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0D2C5C3-225C-49DC-B9C7-C5BC05900F2E" }, { "criteria": "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:professional:*:*:*", "vulnerable": true, "matchCriteriaId": "F6E69C81-2894-4319-9FBD-60AE719942E9" }, { "criteria": "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:standard:*:*:*", "vulnerable": true, "matchCriteriaId": "8BC60369-95D2-475B-9FDA-5D1C13FEE8DF" }, { "criteria": "cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "511E22C6-DB04-44A0-906D-F432DD42CA5C" }, { "criteria": "cpe:2.3:a:microsoft:visio:2003:*:*:*:professional:*:*:*", "vulnerable": true, "matchCriteriaId": "9BF7D109-38E6-4FEE-8F9B-9A481D50DCFA" }, { "criteria": "cpe:2.3:a:microsoft:visio:2003:*:*:*:standard:*:*:*", "vulnerable": true, "matchCriteriaId": "3D931561-2312-4770-B418-FB622856DF34" }, { "criteria": "cpe:2.3:a:microsoft:visio:2003:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FBEFBED-72F3-447B-8164-9E5C16828484" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2002:gold:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E17BD019-DD35-413E-ACBA-2E77C8A1247D" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2003:*:*:*:enterprise_architect:*:*:*", "vulnerable": true, "matchCriteriaId": "A681100F-9DE5-4BE6-ADE9-64A3808C7CDE" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2003:gold:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9E6C132-4F4B-4FB0-9DDC-DD9750D8552D" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:academic:*:*:*", "vulnerable": true, "matchCriteriaId": "AEC99110-8EC1-4FEC-9535-B27AF1965DBF" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:enterprise_architect:*:*:*", "vulnerable": true, "matchCriteriaId": "B35FE238-4380-41C7-A956-EA3F2D5F9159" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:enterprise_developer:*:*:*", "vulnerable": true, "matchCriteriaId": "A8E772B4-8E7D-4D35-8C59-5959123AA572" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:professional:*:*:*", "vulnerable": true, "matchCriteriaId": "4AFEC24E-5FA5-4653-BBAA-AFEBCC3F149B" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:trial:*:*:*", "vulnerable": true, "matchCriteriaId": "D451D000-00DC-46A9-9D1E-2C715D6D1787" } ], "operator": "OR" } ] } ]