Back

CVE-2005-0056

Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
microsoft ie 6
microsoft internet_explorer 5.01
microsoft internet_explorer 5.5

GitHub Security Advisory GHSA-gq77-wfp4-xgg9

Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 28.33%

Top 2% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub