CVE-1999-0891
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 43%
from disclosure to weapon0 days
Published on NVDJan 4
1st PoCSep 27
exploitation probability
43%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/19530⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-040http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ242542http://www.ciac.org/ciac/bulletins/k-002.shtmlhttp://www.kb.cert.org/vuls/id/37828http://www.osvdb.org/11274http://www.securityfocus.com/bid/674