← All CVEs

CVE-2004-0216

high · 10

Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.

10
CVSS
48.7%
EPSS (exploit prob.)
99th
EPSS percentile
2004-11-03
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
microsoftie6
microsoftinternet_explorer5.01
microsoftinternet_explorer5.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0216