CVE-2004-0841

Published Dec 23, 2004

Last updated 3 months ago

Overview

Description
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
Source
cve@mitre.org
NVD status
Modified
Products
ip600_media_servers, ie, internet_explorer, definity_one_media_server, s3400, s8100, modular_messaging_message_storage_server

Risk scores

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.