Back
CVE-2001-0332
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.
Published: Jun 27, 2001
Modified: Apr 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | 5.01 |
| microsoft | internet_explorer | 5.5 |
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
5.70%
Top 8% most likely to be exploited
Threat Score
21.7 / 100
Data Sources
NVD
EPSS