Back

CVE-2005-0053

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (35)

Vendor Product Version
microsoft ie 6.0
microsoft ie 6.0
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise_64-bit
microsoft windows_2003_server r2
microsoft windows_2003_server r2

…and 15 more

GitHub Security Advisory GHSA-xj59-9vch-c6qw

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 59.78%

Top 1% most likely to be exploited

Threat Score 47.9 / 100

Data Sources

NVD EPSS GitHub