CVE

Id
3153  
CVE No.
CVE-2001-0332  
Status
Candidate  
Description
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.  
Phase
Proposed (20010524)  
Votes
ACCEPT(4) Baker, Cole, Wall, Ziese | MODIFY(1) Frech | NOOP(1) Renaud | RECAST(1) Williams | REJECT(1) Magdych | REVIEWING(1) Christey  
Comments
Magdych> Duplicate of CVE-0246 | Christey> While it may look like CVE-2001-0332 is a duplicate of | CVE-2001-0246, Microsoft specifically identifies two separate | variants of the same problem in its advisory, namely 0332 and | 0246. However, CD:SF-LOC currently suggests merging problems | of the same type that appear and are fixed in the same | software versions, and thus these 2 candidates *might* | in fact be duplicates - relative to CD:SF-LOC. Microsoft | needs to be consulted on this. | Williams> merge with CVE-0246 | Frech> XF:ie-frame-verification-read-files(6086) | XF:ie-frame-verification-variant(6748) | CVE-2001-0092 is also assigned to the | ie-frame-verification-files(6086), but shouldn"t be considered a | duplicate.