CVE-2001-0154
UnknownEPSS 11.21%
Last modified
CVE-2001-0154 is a vulnerability of currently unknown severity. HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.. EPSS estimates a 11.21% chance of exploitation in the next 30 days.
Description
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | <= 5.5 |
| Microsoft | Internet Explorer | 5.01 |
References
- http://www.cert.org/advisories/CA-2001-06.htmlUS Government Resource
- http://www.cert.org/advisories/CA-2001-06.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0154?
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
How severe is CVE-2001-0154?
Severity scoring for CVE-2001-0154 is pending analysis. The EPSS model estimates a 11.21% probability of exploitation in the next 30 days.
How do I fix CVE-2001-0154?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0148The WMP ActiveX Control in Windows Media Player 7 allows rem…
- CVE-2001-0149Windows Scripting Host in Internet Explorer 5.5 and earlier …
- CVE-2001-0150Internet Explorer 5.5 and earlier executes Telnet sessions u…
- CVE-2001-0151IIS 5.0 allows remote attackers to cause a denial of service…
- CVE-2001-0152The password protection option for the Compressed Folders fe…
- CVE-2001-0153Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in…
- CVE-2001-0155Format string vulnerability in VShell SSH gateway 1.0.1 and …
- CVE-2001-0156VShell SSH gateway 1.0.1 and earlier has a default port forw…
- CVE-2001-0157Debugging utility in the backdoor mode of Palm OS 3.5.2 and …
- CVE-2001-0160Lucent/ORiNOCO WaveLAN cards generate predictable Initializa…
- CVE-2001-0161Cisco 340-series Aironet access point using firmware 11.01 d…
- CVE-2001-0162WinCE 3.0.9348 generates predictable TCP Initial Sequence Nu…
Are you affected by CVE-2001-0154?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
