CVE-2004-0841

Published Dec 23, 2004

Last updated 10 days ago

Overview

Description
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
Source
cve@mitre.org
NVD status
Modified
Products
ip600_media_servers, ie, internet_explorer, definity_one_media_server, s3400, s8100, modular_messaging_message_storage_server

Risk scores

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.