VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2003-1505Dec 31, 2003
    risk 0.04cvss —epss 0.13

    Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.

  • CVE-2003-0447Jul 24, 2003
    risk 0.04cvss —epss 0.14

    The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.

  • CVE-2002-1688Dec 31, 2002
    risk 0.04cvss —epss 0.17

    The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back…

  • CVE-2002-1705Dec 31, 2002
    risk 0.04cvss —epss 0.18

    Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.

  • CVE-2002-2062Dec 31, 2002
    risk 0.04cvss —epss 0.13

    Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the…

  • CVE-2002-1187Dec 11, 2002
    risk 0.04cvss —epss 0.15

    Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the or element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the…

  • CVE-2002-0862Oct 4, 2002
    risk 0.04cvss —epss 0.16

    The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly…

  • CVE-2002-0723Sep 24, 2002
    risk 0.04cvss —epss 0.15

    Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

  • CVE-2002-0976Sep 24, 2002
    risk 0.04cvss —epss 0.14

    Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.

  • CVE-2002-1444Aug 15, 2002
    risk 0.04cvss —epss 0.14

    The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the…

  • CVE-2002-0189May 29, 2002
    risk 0.04cvss —epss 0.14

    Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.

  • CVE-2002-0153Apr 22, 2002
    risk 0.04cvss —epss 0.18

    Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.

  • CVE-2001-1489Dec 31, 2001
    risk 0.04cvss —epss 0.18

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

  • CVE-2001-0664Oct 30, 2001
    risk 0.04cvss —epss 0.18

    Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone…

  • CVE-2001-0643Sep 20, 2001
    risk 0.04cvss —epss 0.11

    Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.

  • CVE-2001-0150Jun 2, 2001
    risk 0.04cvss —epss 0.18

    Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which…

  • CVE-2001-0089Feb 16, 2001
    risk 0.04cvss —epss 0.14

    Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

  • CVE-2000-0400May 13, 2000
    risk 0.04cvss —epss 0.07

    The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.

  • CVE-2000-0156Feb 16, 2000
    risk 0.04cvss —epss 0.13

    Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.

  • CVE-1999-0981Dec 8, 1999
    risk 0.04cvss —epss 0.13

    Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."

Page 38 of 87