peter bassill · operator
$ cve CVE-2005-4717 JSON

CVE-2005-4717 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 16.3% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS16.33% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-31
Last modified2026-06-16

Affected (6)

VendorProduct
microsoftie
microsoftinternet explorer
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows nt
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD