Back

CVE-2005-0054

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
microsoft ie 6
microsoft internet_explorer 5.01
microsoft internet_explorer 5.5

GitHub Security Advisory GHSA-xx2h-39g7-5x2c

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 24.31%

Top 2% most likely to be exploited

Threat Score 27.7 / 100

Data Sources

NVD EPSS GitHub