VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2007-3576Jul 5, 2007
    risk 0.01cvss —epss 0.13

    Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names with 10 or more…

  • CVE-2007-3497Jun 29, 2007
    risk 0.01cvss —epss 0.10

    Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via the history.length JavaScript variable.

  • CVE-2007-3481Jun 28, 2007
    risk 0.01cvss —epss 0.16

    Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute.…

  • CVE-2007-3341Jun 21, 2007
    risk 0.01cvss —epss 0.11

    Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217.

  • CVE-2007-3164Jun 11, 2007
    risk 0.01cvss —epss 0.10

    Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attackers to perform…

  • CVE-2007-3075Jun 6, 2007
    risk 0.01cvss —epss 0.16

    Directory traversal vulnerability in Microsoft Internet Explorer allows remote attackers to read arbitrary files via directory traversal sequences in a URI with a certain scheme, possibly related to "..%5C" (encoded backslash) sequences.

  • CVE-2007-2292Apr 26, 2007
    risk 0.01cvss —epss 0.13

    CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.

  • CVE-2007-2161Apr 22, 2007
    risk 0.01cvss —epss 0.12

    Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

  • CVE-2007-1114Feb 26, 2007
    risk 0.01cvss —epss 0.12

    The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the…

  • CVE-2007-1094Feb 26, 2007
    risk 0.01cvss —epss 0.18

    Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.

  • CVE-2006-7029Feb 23, 2007
    risk 0.01cvss —epss 0.13

    Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a frameset with only one frame that calls resizeTo with certain arguments. NOTE: this issue might be related to CVE-2006-3637.

  • CVE-2006-7030Feb 23, 2007
    risk 0.01cvss —epss 0.17

    Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.

  • CVE-2006-6956Jan 29, 2007
    risk 0.01cvss —epss 0.11

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.

  • CVE-2006-5884Nov 14, 2006
    risk 0.01cvss —epss 0.07

    Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and…

  • CVE-2006-5152Oct 5, 2006
    risk 0.01cvss —epss 0.11

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an explicit charset, a related issue to CVE-2006-0032.

  • CVE-2006-4888Sep 19, 2006
    risk 0.01cvss —epss 0.17

    Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size than the INPUT.

  • CVE-2006-3658Jul 18, 2006
    risk 0.01cvss —epss 0.13

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by accessing the object references of a FolderItem ActiveX object, which triggers a null dereference in the security check.

  • CVE-2006-3659Jul 18, 2006
    risk 0.01cvss —epss 0.15

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the location or URL property of a MHTMLFile ActiveX object.

  • CVE-2006-3657Jul 18, 2006
    risk 0.01cvss —epss 0.17

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow exception) via a DXImageTransform.Microsoft.Gradient ActiveX object with a long (1) StartColorStr or (2) EndColorStr property.

  • CVE-2006-3545Jul 13, 2006
    risk 0.01cvss —epss 0.14

    Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet…

Page 78 of 87