VDB
CVE-2004-0843
CVE-2004-0843
PUBLISHED
CVSS 5 MEDIUM
Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
EPSS 42.84% · 97.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
42.84%
97.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | ie | 6 |
| microsoft | internet_explorer | 5.5 |
| n/a | n/a | * |
Timeline
- Oct 16, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- VU#625616 third-party-advisory
- MS04-038 vendor-advisory
- oval:org.mitre.oval:def:7095 vdb
- oval:org.mitre.oval:def:7194 vdb
- oval:org.mitre.oval:def:2487 vdb
- TA04-293A third-party-advisory
- ie-ms04038-patch(17651) vdb
- oval:org.mitre.oval:def:2537 vdb
- ie-plugin-address-spoofing(17655) vdb
- oval:org.mitre.oval:def:3949 vdb
- oval:org.mitre.oval:def:6313 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-0843 advisory