CVE-1999-1016 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7.7% (pctl 94)
Patch early
A public exploit exists.
Description
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 7.7% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 1999-08-27 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | frontpage |
| microsoft | internet explorer |
| microsoft | outlook express |
| qualcomm | eudora |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 5 - HTML Form Control Denial of Service | 1999-08-27 |
References
→ the Explorer · watch your stack · NVD