Vulnerability record · CVE-2005-0554 · published 2 May 2005
CVE-2005-0554: Microsoft Internet Explorer URL processor buffer overflow
Microsoft · Internet Explorer
Internet Explorer 5.01, 5.5 and 6 contain a buffer overflow in the URL processor triggered by a URL with an overly long hostname. The flaw is remotely reachable and can crash the browser or potentially allow arbitrary code execution in the context of the user.
Description
Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution potential in a widely deployed browser, with a high EPSS score despite no KEV listing.
What it is
Internet Explorer 5.01, 5.5 and 6 contain a buffer overflow in the URL processor triggered by a URL with an overly long hostname. The flaw is remotely reachable and can crash the browser or potentially allow arbitrary code execution in the context of the user.
Impact
An attacker can crash the browser and possibly execute arbitrary code with the privileges of the logged-on user, giving a path to full system compromise if the user has administrative rights.
Attack surface
Reached over the network by getting a victim to load a crafted URL, typically via a malicious web page or link; no authentication is required, but user interaction (visiting the page or clicking the link) is needed.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, though EPSS is high at 0.5791 (99th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Apply Microsoft security bulletin MS05-020 (the vendor patch referenced in the record) or upgrade to a supported browser version.
- Retire or isolate Internet Explorer 5.01, 5.5 and 6, which are long out of support.
- Enforce a modern browser as default and block legacy IE execution where possible.
- Filter or inspect URLs with abnormally long hostnames at web proxies and email gateways.
- Restrict user privileges so browser compromise does not yield administrative access.
Detection
- Monitor browser crash reports and endpoint logs for iexplore.exe faults tied to URL navigation.
- Inspect proxy and DNS logs for requests with unusually long hostnames.
- Alert on legacy IE versions (5.01, 5.5, 6) appearing in asset inventories or process telemetry.
- Review email and web gateway logs for links with oversized hostname fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0554 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.