Back

CVE-2003-0532

Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.

Published: Aug 27, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
microsoft ie 6.0
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-v4mq-xcq7-hmfv

Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 22.96%

Top 2% most likely to be exploited

Threat Score 36.9 / 100

Data Sources

NVD EPSS GitHub