CVE-2004-1686
Last modified
CVE-2004-1686 is a vulnerability of currently unknown severity. Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.. EPSS estimates a 10.27% chance of exploitation in the next 30 days.
Description
Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Ie | 6.0 | Sp2 |
References
- http://www.securityfocus.com/bid/11200Vendor Advisory
- http://www.securityfocus.com/bid/11200Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1686?
How severe is CVE-2004-1686?
How do I fix CVE-2004-1686?
Are you affected by CVE-2004-1686?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
