CVE-2002-0022
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 40%
exploitation probability
40%top 1% of all CVEs
observed exploitation
nono source reports it
Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.
Affected products
n/a · n/aReferences
http://marc.info/?l=bugtraq&m=101362984930597&w=2http://online.securityfocus.com/archive/1/258614https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-005https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A925http://www.cert.org/advisories/CA-2002-04.htmlhttp://www.iss.net/security_center/static/8116.phphttp://www.securityfocus.com/bid/4080