Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
Published Jul 23, 2004
7.5
HIGHCVSS 2.0
EPSS 39.78%
Description
Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."
Affected products
No data.
- 6.0.2800.1106
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 39.78% (0.39782) | 98.58th | v5 (v2026.06.15) |
| Jun 15, 2026 | 39.78% (0.39782) | 98.44th | v5 (v2026.06.15) |
| Mar 28, 2026 | 57.58% (0.57584) | 98.15th | v4 (v2025.03.14) |
| Jun 17, 2025 | 64.05% (0.64045) | 98.30th | v4 (v2025.03.14) |
| Mar 30, 2025 | 58.31% (0.58314) | 98.01th | v4 (v2025.03.14) |
| Mar 29, 2025 | 61.55% (0.61552) | 97.61th | v4 (v2025.03.14) |
| Mar 17, 2025 | 57.45% (0.57454) | 97.93th | v4 (v2025.03.14) |
| Dec 12, 2024 | 5.61% (0.05613) | 93.55th | v3 (v2023.03.01) |
| Aug 7, 2024 | 5.61% (0.05613) | 93.35th | v3 (v2023.03.01) |
| Jun 30, 2023 | 7.74% (0.07735) | 93.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.12% (0.03117) | 89.54th | v3 (v2023.03.01) |
| Mar 6, 2023 | 42.58% (0.42578) | 98.30th | v2 (v2022.01.01) |
| Feb 4, 2022 | 42.58% (0.42578) | 97.61th | v2 (v2022.01.01) |
No CWE recorded.
References (13)
- http://freehost07.websamba.com/greyhats/similarmethodnameredir.htm x_refsource_MISC
- http://marc.info/?l=bugtraq&m=108966512815373&w=2 mailing-listx_refsource_BUGTRAQ
- http://secunia.com/advisories/12048 third-party-advisoryx_refsource_SECUNIA
- http://www.kb.cert.org/vuls/id/207264 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-293A.html third-party-advisoryx_refsource_CERTUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038 vendor-advisoryx_refsource_MS
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16681 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4702 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6829 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7084 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7448 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7496 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7906 vdb-entrysignaturex_refsource_OVAL
Change history (0)
No recorded changes yet.