CVE-2005-2829 Information

Description

Multiple design errors in Microsoft Internet Explorer 5.01 5.5 and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the \Run\ button aka \File Download Dialog Box Manipulation Vulnerability.\

Reference

http://marc.info/?l=full-disclosure&m=113450519906463&w=2 http://secunia.com/advisories/15368 http://secunia.com/advisories/18064 http://secunia.com/advisories/18311 http://secunia.com/secunia_research/2005-21/advisory http://secunia.com/secunia_research/2005-7/advisory/ http://securityreason.com/securityalert/254 http://securitytracker.com/id?1015349 http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf http://www.securityfocus.com/archive/1/419395/100/0/threaded http://www.securityfocus.com/bid/15823 http://www.vupen.com/english/advisories/2005/2867 http://www.vupen.com/english/advisories/2005/2909 http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375420 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-054 https://exchange.xforce.ibmcloud.com/vulnerabilities/23448 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1209 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1340 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1458 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1490 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1505 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1507

Share on: