Back

CVE-2000-0464

Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.

Published: May 17, 2000 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
microsoft internet_explorer 4.0
microsoft internet_explorer 4.0.1
microsoft internet_explorer 5.0
microsoft internet_explorer 5.01

GitHub Security Advisory GHSA-p267-cj3r-wj88

Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer...

Risk Scores

CVSS Score 7.6 / 10
EPSS Score 15.08%

Top 5% most likely to be exploited

Threat Score 34.9 / 100

Data Sources

NVD EPSS GitHub