VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2007-1751Jun 12, 2007
    risk 0.05cvss —epss 0.61

    Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."

  • CVE-2007-1499Mar 17, 2007
    risk 0.05cvss —epss 0.30

    Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation…

  • CVE-2006-7065Mar 2, 2007
    risk 0.05cvss —epss 0.20

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.

  • CVE-2006-7066Mar 2, 2007
    risk 0.05cvss —epss 0.22

    Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame,…

  • CVE-2006-6311Dec 6, 2006
    risk 0.05cvss —epss 0.26

    Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.

  • CVE-2006-4495Aug 31, 2006
    risk 0.05cvss —epss 0.21

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.

  • CVE-2006-3915Jul 28, 2006
    risk 0.05cvss —epss 0.22

    Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.

  • CVE-2006-3899Jul 27, 2006
    risk 0.05cvss —epss 0.24

    Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid memory access inside…

  • CVE-2006-3897Jul 27, 2006
    risk 0.05cvss —epss 0.23

    Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.

  • CVE-2006-3898Jul 27, 2006
    risk 0.05cvss —epss 0.24

    Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method of the Internet.HHCtrl.1 ActiveX object before initializing the URL, which triggers a null dereference.

  • CVE-2006-3729Jul 21, 2006
    risk 0.05cvss —epss 0.21

    DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, which leads to an integer…

  • CVE-2006-3605Jul 18, 2006
    risk 0.05cvss —epss 0.24

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.

  • CVE-2006-3591Jul 18, 2006
    risk 0.05cvss —epss 0.26

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference.

  • CVE-2006-3513Jul 11, 2006
    risk 0.05cvss —epss 0.23

    danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.

  • CVE-2006-3512Jul 11, 2006
    risk 0.05cvss —epss 0.24

    Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX object to true, which triggers a null dereference.

  • CVE-2006-3511Jul 11, 2006
    risk 0.05cvss —epss 0.22

    Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the fonts property of the HtmlDlgSafeHelper object, which triggers a null dereference.

  • CVE-2006-3471Jul 10, 2006
    risk 0.05cvss —epss 0.21

    Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method.

  • CVE-2006-3427Jul 7, 2006
    risk 0.05cvss —epss 0.24

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.

  • CVE-2006-2094Apr 29, 2006
    risk 0.05cvss —epss 0.23

    Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows…

  • CVE-2006-1626Apr 5, 2006
    risk 0.05cvss —epss 0.26

    Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash…

Page 34 of 87