VULNERABILITY INTELLIGENCE
CVE-2005-1990
CVSS score5.1 MEDIUM
EPSS probability48.51%
CISA KEVNot currently listed
Published2005-08-10
Last modified2026-06-16
Description
Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2... .