VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2003-0530Aug 27, 2003
    risk 0.02cvss —epss 0.30

    Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.

  • CVE-2003-0531Aug 27, 2003
    risk 0.02cvss —epss 0.27

    Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.

  • CVE-2003-0532Aug 27, 2003
    risk 0.02cvss —epss 0.23

    Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an…

  • CVE-2003-0233May 12, 2003
    risk 0.02cvss —epss 0.19

    Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.

  • CVE-2003-0116May 12, 2003
    risk 0.02cvss —epss 0.25

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target…

  • CVE-2002-1186Dec 11, 2002
    risk 0.02cvss —epss 0.19

    Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka…

  • CVE-2002-1185Dec 11, 2002
    risk 0.02cvss —epss 0.21

    Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka…

  • CVE-2002-1286Nov 29, 2002
    risk 0.02cvss —epss 0.20

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious…

  • CVE-2002-0190May 29, 2002
    risk 0.02cvss —epss 0.24

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.

  • CVE-2002-0078Mar 29, 2002
    risk 0.02cvss —epss 0.22

    The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.

  • CVE-2002-0057Mar 8, 2002
    risk 0.02cvss —epss 0.19

    XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.

  • CVE-2002-0027Mar 8, 2002
    risk 0.02cvss —epss 0.19

    Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability…

  • CVE-2001-0727Dec 14, 2001
    risk 0.02cvss —epss 0.31

    Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution…

  • CVE-2001-0874Dec 13, 2001
    risk 0.02cvss —epss 0.22

    Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes information from a frame in the client's domain to a frame in the web site's domain, a variant of the "Frame Domain Verification" vulnerability.

  • CVE-2001-0002Jul 21, 2001
    risk 0.02cvss —epss 0.20

    Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.

  • CVE-2000-0662Jul 14, 2000
    risk 0.02cvss —epss 0.21

    Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).

  • CVE-2000-0596Jun 27, 2000
    risk 0.02cvss —epss 0.25

    Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.

  • CVE-2015-6164Dec 9, 2015
    risk 0.01cvss —epss 0.12

    Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability."

  • CVE-2015-6162Dec 9, 2015
    risk 0.01cvss —epss 0.13

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6152.

  • CVE-2015-6158Dec 9, 2015
    risk 0.01cvss —epss 0.17

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140,…

Page 58 of 87