Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-1497

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2001-1497
Last Modified 05 Sep 2008 04:26:42
Published 31 Dec 2001 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2001-1497

Summary

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.

Vulnerable Systems

Application

  • Microsoft Ie 4.0

  • Microsoft Ie 4.0.1

  • Microsoft Ie 4.1

  • Microsoft Ie 5.5

  • Microsoft Ie 6.0


References

BID - 3563

BUGTRAQ - 20011120 Re: MS IE Password inputs

BUGTRAQ - 20011121 MS IE Password inputs

XF - ie-password-character-information(7592)


Last Updated: 27 May 2016 10:36:42