Back

CVE-2001-0338

Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."

Published: Jun 27, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_explorer *
microsoft internet_explorer 5.01

GitHub Security Advisory GHSA-fm3g-qc6p-8vwh

Internet Explorer 5.5 and earlier does not properly validate digital certificates when...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 5.32%

Top 8% most likely to be exploited

Threat Score 22 / 100

Data Sources

NVD EPSS GitHub