CVE Database
/

CVE-2005-2127

Back to search

CVE-2005-2127

Published: Aug 19, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#959049
third-party-advisory
x_refsource_CERT-VN
72
third-party-advisory
x_refsource_SREASON
TA05-347A
third-party-advisory
x_refsource_CERT
MS05-052
vendor-advisory
x_refsource_MS
15061
vdb-entry
x_refsource_BID
17223
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:1454
vdb-entry
signature
x_refsource_OVAL
16480
third-party-advisory
x_refsource_SECUNIA
microsoft-ie-mshtml-dos(34754)
vdb-entry
x_refsource_XF
17172
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:1538
vdb-entry
signature
x_refsource_OVAL
Win-msdss-command-execution(21895)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:1535
vdb-entry
signature
x_refsource_OVAL
14594
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:1468
vdb-entry
signature
x_refsource_OVAL
17509
third-party-advisory
x_refsource_SECUNIA
TA06-220A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:1464
vdb-entry
signature
x_refsource_OVAL
VU#740372
third-party-advisory
x_refsource_CERT-VN
VU#898241
third-party-advisory
x_refsource_CERT-VN
1014727
vdb-entry
x_refsource_SECTRACK
TA05-284A
third-party-advisory
x_refsource_CERT
ADV-2005-1450
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:1155
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now