Back

CVE-2005-0055

Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
microsoft ie 6.0
microsoft ie 6.0
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-729m-r9fv-3cr3

Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 36.84%

Top 2% most likely to be exploited

Threat Score 41.1 / 100

Data Sources

NVD EPSS GitHub