VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2002-0101Mar 25, 2002
    risk 0.01cvss —epss 0.12

    Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.

  • CVE-2002-0052Mar 8, 2002
    risk 0.01cvss —epss 0.18

    Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.

  • CVE-2002-0025Mar 8, 2002
    risk 0.01cvss —epss 0.14

    Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, which allows remote attackers to modify which application is used to process a document.

  • CVE-2002-0026Mar 8, 2002
    risk 0.01cvss —epss 0.13

    Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.

  • CVE-2002-0077Jan 13, 2002
    risk 0.01cvss —epss 0.11

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the…

  • CVE-2001-1539Dec 31, 2001
    risk 0.01cvss —epss 0.14

    Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem.

  • CVE-2001-0807Dec 6, 2001
    risk 0.01cvss —epss 0.07

    Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.

  • CVE-2001-0904Nov 20, 2001
    risk 0.01cvss —epss 0.07

    Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.

  • CVE-2001-0723Nov 14, 2001
    risk 0.01cvss —epss 0.11

    Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."

  • CVE-2001-0724Nov 14, 2001
    risk 0.01cvss —epss 0.12

    Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing…

  • CVE-2001-0665Oct 30, 2001
    risk 0.01cvss —epss 0.12

    Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding…

  • CVE-2001-0339Jun 27, 2001
    risk 0.01cvss —epss 0.15

    Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."

  • CVE-2001-1450May 11, 2001
    risk 0.01cvss —epss 0.07

    Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".

  • CVE-2001-0154May 3, 2001
    risk 0.01cvss —epss 0.11

    HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.

  • CVE-2001-0092Feb 16, 2001
    risk 0.01cvss —epss 0.12

    A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.

  • CVE-2000-0982Dec 19, 2000
    risk 0.01cvss —epss 0.13

    Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.

  • CVE-2000-0768Oct 20, 2000
    risk 0.01cvss —epss 0.10

    A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.

  • CVE-2000-0503Jun 6, 2000
    risk 0.01cvss —epss 0.09

    The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.

  • CVE-2000-0464May 17, 2000
    risk 0.01cvss —epss 0.13

    Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.

  • CVE-2000-0439May 11, 2000
    risk 0.01cvss —epss 0.06

    Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.

Page 82 of 87