Back
CVE-2001-0664
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."
Published: Oct 30, 2001
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | 5.01 |
| microsoft | internet_explorer | 5.5 |
GitHub Security Advisory GHSA-35hr-3jc6-7qrp
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via...
References (12)
- http://marc.info/?l=bugtraq&m=100281551611595&w=2
- http://morph3us.org/blog/?p=31
- http://www.osvdb.org/1971
- http://www.securityfocus.com/bid/3420
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7258
- http://marc.info/?l=bugtraq&m=100281551611595&w=2
- http://morph3us.org/blog/?p=31
- http://www.osvdb.org/1971
- http://www.securityfocus.com/bid/3420
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7258
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
18.19%
Top 3% most likely to be exploited
Threat Score
35.5 / 100
Data Sources
NVD
EPSS
GitHub