CyberRota
Live Feed
Return to register
Case File

CVE-2005-1990

MEDIUM · CVSS 5.1 EPSS 48.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-08-10 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2005-1990
Severity
MEDIUM
CVSS
5.1
EPSS
48.51%

Original Filing — NVD Description

Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.