← Back

CVE-2005-0056

nvd nist
Published: May 2, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."

Affected (3)

2 products
Ie
Internet Explorer
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 6 windows_server_2003_sp1
Microsoft
Version 5.01
Version 5.5

References (22)

Source: cve@mitre.org
PatchUS Government Resource
Source: cve@mitre.org
ExploitPatch
Source: cve@mitre.org
PatchUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.