VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2013-2552Mar 11, 2013
    risk 0.01cvss —epss 0.14

    Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.

  • CVE-2013-0023Feb 13, 2013
    risk 0.01cvss —epss 0.19

    Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CDispNode Use After Free Vulnerability."

  • CVE-2013-0015Feb 13, 2013
    risk 0.01cvss —epss 0.16

    Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS encoding, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers cross-domain scrolling events, aka "Shift JIS…

  • CVE-2013-1450Jan 29, 2013
    risk 0.01cvss —epss 0.09

    Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for…

  • CVE-2012-6502Jan 22, 2013
    risk 0.01cvss —epss 0.10

    Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a…

  • CVE-2012-4781Dec 12, 2012
    risk 0.01cvss —epss 0.18

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "InjectHTMLStream Use After Free Vulnerability."

  • CVE-2012-1882Jun 12, 2012
    risk 0.01cvss —epss 0.14

    Microsoft Internet Explorer 6 through 9 does not block cross-domain scrolling events, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Scrolling Events Information Disclosure Vulnerability."

  • CVE-2012-1873Jun 12, 2012
    risk 0.01cvss —epss 0.18

    Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which allows remote attackers to obtain sensitive information from process memory via a crafted HTML document, aka "Null Byte Information Disclosure Vulnerability."

  • CVE-2012-0168Apr 10, 2012
    risk 0.01cvss —epss 0.18

    Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document that is not properly handled during a "Print table of links" print operation, aka "Print Feature Remote Code Execution Vulnerability."

  • CVE-2012-0012Feb 14, 2012
    risk 0.01cvss —epss 0.17

    Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."

  • CVE-2012-0010Feb 14, 2012
    risk 0.01cvss —epss 0.14

    Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Copy and Paste Information Disclosure Vulnerability."

  • CVE-2011-3404Dec 14, 2011
    risk 0.01cvss —epss 0.14

    Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka…

  • CVE-2011-2019Dec 14, 2011
    risk 0.01cvss —epss 0.11

    Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an…

  • CVE-2011-4689Dec 7, 2011
    risk 0.01cvss —epss 0.09

    Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript…

  • CVE-2010-5071Dec 7, 2011
    risk 0.01cvss —epss 0.13

    The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by…

  • CVE-2002-2435Dec 7, 2011
    risk 0.01cvss —epss 0.14

    The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue…

  • CVE-2011-1997Oct 12, 2011
    risk 0.01cvss —epss 0.14

    Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnLoad Event Remote Code Execution Vulnerability."

  • CVE-2011-1993Oct 12, 2011
    risk 0.01cvss —epss 0.18

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Scroll Event Remote Code Execution Vulnerability."

  • CVE-2011-1962Aug 10, 2011
    risk 0.01cvss —epss 0.13

    Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers "inactive filtering," aka "Shift JIS Character Encoding…

  • CVE-2011-1960Aug 10, 2011
    risk 0.01cvss —epss 0.18

    Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Event Handlers Information Disclosure Vulnerability."

Page 74 of 87