Back

CVE-2002-0077

Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.

Published: Jan 13, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-4q4q-pr45-j3xr

Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 11.47%

Top 4% most likely to be exploited

Threat Score 33.4 / 100

Data Sources

NVD EPSS GitHub