CVE-2005-0054

5.1
CVSS v2.0 Base Score
24.30%
LOW RiskEPSS (98th percentile)
NVD-CWE-Other

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

Published: 5/2/2005
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

5.1

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

24.30%LOW Exploitation Risk
98th percentile

This vulnerability has a 24.30% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

CWE Classification

NVD-CWE-Other
Advertisement