VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2005-0500May 2, 2005
    risk 0.01cvss —epss 0.11

    Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.

  • CVE-2005-0110Jan 14, 2005
    risk 0.01cvss —epss 0.07

    Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement…

  • CVE-2004-2011Dec 31, 2004
    risk 0.01cvss —epss 0.07

    msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a link, which triggers a parsing error, possibly due to missing portions of the URI.

  • CVE-2004-2219Dec 31, 2004
    risk 0.01cvss —epss 0.08

    Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.

  • CVE-2004-2476Dec 31, 2004
    risk 0.01cvss —epss 0.09

    Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.

  • CVE-2004-2307Dec 31, 2004
    risk 0.01cvss —epss 0.15

    Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A.

  • CVE-2004-1155Dec 31, 2004
    risk 0.01cvss —epss 0.13

    Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window…

  • CVE-2004-1173Dec 31, 2004
    risk 0.01cvss —epss 0.12

    Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog.

  • CVE-2004-1376Dec 30, 2004
    risk 0.01cvss —epss 0.09

    Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.

  • CVE-2004-0867Dec 23, 2004
    risk 0.01cvss —epss 0.17

    Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is…

  • CVE-2004-0284Nov 23, 2004
    risk 0.01cvss —epss 0.17

    Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.

  • CVE-2004-0866Sep 16, 2004
    risk 0.01cvss —epss 0.10

    Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

  • CVE-2003-0513Apr 15, 2004
    risk 0.01cvss —epss 0.10

    Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g.…

  • CVE-2004-1922Apr 11, 2004
    risk 0.01cvss —epss 0.07

    Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.

  • CVE-2003-0815Feb 3, 2004
    risk 0.01cvss —epss 0.19

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the…

  • CVE-2003-0817Feb 3, 2004
    risk 0.01cvss —epss 0.18

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.

  • CVE-2003-1484Dec 31, 2003
    risk 0.01cvss —epss 0.11

    Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.

  • CVE-2003-1105Dec 31, 2003
    risk 0.01cvss —epss 0.18

    Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.

  • CVE-2003-1559Dec 31, 2003
    risk 0.01cvss —epss 0.16

    Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

  • CVE-2003-0519Aug 18, 2003
    risk 0.01cvss —epss 0.11

    Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.

Page 80 of 87