VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2000-0028Dec 23, 1999
    risk 0.05cvss —epss 0.23

    Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

  • CVE-1999-1577Oct 31, 1999
    risk 0.05cvss —epss 0.19

    Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.

  • CVE-1999-1578Sep 24, 1999
    risk 0.05cvss —epss 0.19

    Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.

  • CVE-1999-0702Sep 10, 1999
    risk 0.05cvss —epss 0.24

    Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

  • CVE-1999-0668Aug 21, 1999
    risk 0.05cvss —epss 0.23

    The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

  • CVE-2014-1778Jun 11, 2014
    risk 0.04cvss —epss 0.15

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.

  • CVE-2014-1771Jun 11, 2014
    risk 0.04cvss —epss 0.08

    SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a…

  • CVE-2013-5045Dec 11, 2013
    risk 0.04cvss —epss 0.17

    Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."

  • CVE-2013-3166Jul 10, 2013
    risk 0.04cvss —epss 0.16

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via vectors involving incorrect auto-selection of the Shift JIS encoding, leading to cross-domain scrolling events, aka "Shift JIS…

  • CVE-2010-3886Oct 8, 2010
    risk 0.04cvss —epss 0.17

    The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about…

  • CVE-2010-3324Sep 17, 2010
    risk 0.04cvss —epss 0.25

    The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the…

  • CVE-2010-1175Mar 29, 2010
    risk 0.04cvss —epss 0.14

    Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."

  • CVE-2009-3019Aug 31, 2009
    risk 0.04cvss —epss 0.17

    Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and then calls setAttribute…

  • CVE-2009-2764Aug 14, 2009
    risk 0.04cvss —epss 0.11

    Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script…

  • CVE-2009-2350Jul 7, 2009
    risk 0.04cvss —epss 0.14

    Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the…

  • CVE-2009-1335Apr 17, 2009
    risk 0.04cvss —epss 0.16

    Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.

  • CVE-2009-0369Jan 30, 2009
    risk 0.04cvss —epss 0.11

    Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.

  • CVE-2009-0341Jan 29, 2009
    risk 0.04cvss —epss 0.16

    The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.

  • CVE-2008-5551Dec 12, 2008
    risk 0.04cvss —epss 0.14

    The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a…

  • CVE-2008-4787Oct 29, 2008
    risk 0.04cvss —epss 0.14

    Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ticket MSRC7899, a related…

Page 36 of 87