VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2006-3227Jun 26, 2006
    risk 0.01cvss —epss 0.14

    Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters via ASCII characters with…

  • CVE-2006-3200Jun 23, 2006
    risk 0.01cvss —epss 0.16

    Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash) via an IFRAME with a src tag containing a "File://" URI followed by an 8-bit character. NOTE: some third parties were unable to verify this issue.

  • CVE-2006-2056Apr 26, 2006
    risk 0.01cvss —epss 0.13

    Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook…

  • CVE-2006-0830Feb 21, 2006
    risk 0.01cvss —epss 0.14

    The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as…

  • CVE-2006-0799Feb 19, 2006
    risk 0.01cvss —epss 0.08

    Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that…

  • CVE-2006-0753Feb 18, 2006
    risk 0.01cvss —epss 0.12

    Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.

  • CVE-2006-0585Feb 8, 2006
    risk 0.01cvss —epss 0.15

    jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function,…

  • CVE-2005-4844Dec 31, 2005
    risk 0.01cvss —epss 0.12

    The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

  • CVE-2005-4810Dec 31, 2005
    risk 0.01cvss —epss 0.14

    Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).

  • CVE-2005-4827Dec 31, 2005
    risk 0.01cvss —epss 0.11

    Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return…

  • CVE-2005-4841Dec 31, 2005
    risk 0.01cvss —epss 0.09

    The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

  • CVE-2005-4842Dec 31, 2005
    risk 0.01cvss —epss 0.09

    The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

  • CVE-2005-4843Dec 31, 2005
    risk 0.01cvss —epss 0.11

    The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

  • CVE-2005-2829Dec 14, 2005
    risk 0.01cvss —epss 0.19

    Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box…

  • CVE-2005-3312Oct 26, 2005
    risk 0.01cvss —epss 0.12

    The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on the link, even though the…

  • CVE-2005-2126Oct 21, 2005
    risk 0.01cvss —epss 0.14

    The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary…

  • CVE-2005-2304Jul 19, 2005
    risk 0.01cvss —epss 0.09

    Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.

  • CVE-2005-2274Jul 13, 2005
    risk 0.01cvss —epss 0.10

    Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

  • CVE-2005-1829May 28, 2005
    risk 0.01cvss —epss 0.13

    Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.

  • CVE-2005-0954May 2, 2005
    risk 0.01cvss —epss 0.15

    Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.

Page 79 of 87