Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
https://exchange.xforce.ibmcloud.com/vulnerabilities/28512
http://www.xsec.org/index.php?module=Releases&act=view&type=1&id=16
http://www.securityfocus.com/bid/19636
http://www.securityfocus.com/archive/1/443896/100/100/threaded