CVE-2005-0056

medium Microsoft
CVSS v3 Base Score
5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS Score
29.5%
Exploitation probability in 30 days
Top 3% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Confidentiality
P
Integrity
P
Availability
P
Published: May 2, 2005 (7682 days ago)
Last Modified: April 16, 2026
Vendor: Microsoft
Source: NVD

Description

Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."

CWE

NVD-CWE-Other

Affected Products

microsoft iemicrosoft internet explorer

References