Back

CVE-2005-2831

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.

Published: Dec 14, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
microsoft ie 6.0
microsoft ie 6.0
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-h2vf-jw82-xqc6

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 30.14%

Top 2% most likely to be exploited

Threat Score 39 / 100

Data Sources

NVD EPSS GitHub