← All CVEs

CVE-2004-1686

medium · 5

Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.

5
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2004-09-15
Published

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

VendorProductAffected versions
microsoftie6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-1686