VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2006-0544Feb 4, 2006
    risk 0.05cvss —epss 0.22

    urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-"…

  • CVE-2004-2383Dec 31, 2004
    risk 0.05cvss —epss 0.20

    Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the…

  • CVE-2004-0484Jul 7, 2004
    risk 0.05cvss —epss 0.22

    mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table,…

  • CVE-2003-1025Jan 20, 2004
    risk 0.05cvss —epss 0.27

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL…

  • CVE-2003-0809Nov 17, 2003
    risk 0.05cvss —epss 0.27

    Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.

  • CVE-2003-0701Aug 27, 2003
    risk 0.05cvss —epss 0.30

    Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.

  • CVE-2003-0446Jul 24, 2003
    risk 0.05cvss —epss 0.23

    Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error…

  • CVE-2002-2031Dec 31, 2002
    risk 0.05cvss —epss 0.21

    Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results.

  • CVE-2002-1714Dec 31, 2002
    risk 0.05cvss —epss 0.19

    Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.

  • CVE-2002-0647Sep 24, 2002
    risk 0.05cvss —epss 0.23

    Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

  • CVE-2002-0980Sep 24, 2002
    risk 0.05cvss —epss 0.27

    The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml:…

  • CVE-2002-0461Aug 12, 2002
    risk 0.05cvss —epss 0.23

    Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.

  • CVE-2002-0191May 29, 2002
    risk 0.05cvss —epss 0.29

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability.

  • CVE-2001-0722Dec 6, 2001
    risk 0.05cvss —epss 0.28

    Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."

  • CVE-2001-0875Nov 26, 2001
    risk 0.05cvss —epss 0.28

    Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.

  • CVE-2001-0322Jun 2, 2001
    risk 0.05cvss —epss 0.21

    MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.

  • CVE-2001-1325Apr 20, 2001
    risk 0.05cvss —epss 0.27

    Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows…

  • CVE-2000-0465May 17, 2000
    risk 0.05cvss —epss 0.21

    Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.

  • CVE-2000-0105Feb 1, 2000
    risk 0.05cvss —epss 0.21

    Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.

  • CVE-2000-0061Jan 7, 2000
    risk 0.05cvss —epss 0.20

    Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.

Page 35 of 87