MEDIUM · 5.0

CVE-2004-0841

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" an...

Vulnerability Description

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AvayaIp600 Media ServersAll versions
MicrosoftIe6.0
MicrosoftInternet Explorer5.0.1
AvayaDefinity One Media ServerAll versions
AvayaS3400All versions
AvayaS8100All versions
AvayaModular Messaging Message Storage Server1.1

References

FAQ

What is CVE-2004-0841?

CVE-2004-0841 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" an...

How severe is CVE-2004-0841?

CVE-2004-0841 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0841?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Ip600 Media Servers, Microsoft Ie, Microsoft Internet Explorer, Avaya Definity One Media Server, Avaya S3400.