VDB
CVE-2003-0309
CVE-2003-0309
PUBLISHED
CVSS 7.5 HIGH
Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."
EPSS 19.16% · 95.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
19.16%
95.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| microsoft | internet_explorer | 6.0.2800 |
Timeline
- May 17, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 26, 2023 EPSS Score
References
- 8807 third-party-advisory
- 20030508 Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! [CRITICAL] mailing-list
- VU#251788 third-party-advisory
- oval:org.mitre.oval:def:948 vdb
- 20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! - UPDATED mailing-list
- 7539 vdb
- 20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! - UPDATED mailing-list
- MS03-020 vendor-advisory
- ie-frame-restrictions-bypass(12019) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2003-0309 advisory