peter bassill · operator
$ cve CVE-2001-0664 JSON

CVE-2001-0664 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 18.2% (pctl 97)

Patch early

A public exploit exists.

Description

Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS18.19% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2001-10-30
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD