Internet Explorer
by Microsoft
CVEs (1,731)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2002-0101 | 0.01 | — | 0.12 | Mar 25, 2002 | Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released. | |||
| CVE-2002-0052 | 0.01 | — | 0.18 | Mar 8, 2002 | Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files. | |||
| CVE-2002-0025 | 0.01 | — | 0.14 | Mar 8, 2002 | Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, which allows remote attackers to modify which application is used to process a document. | |||
| CVE-2002-0026 | 0.01 | — | 0.13 | Mar 8, 2002 | Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made. | |||
| CVE-2002-0077 | 0.01 | — | 0.11 | Jan 13, 2002 | Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the… | |||
| CVE-2001-1539 | 0.01 | — | 0.14 | Dec 31, 2001 | Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem. | |||
| CVE-2001-0807 | 0.01 | — | 0.07 | Dec 6, 2001 | Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file. | |||
| CVE-2001-0904 | 0.01 | — | 0.07 | Nov 20, 2001 | Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients. | |||
| CVE-2001-0723 | 0.01 | — | 0.11 | Nov 14, 2001 | Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." | |||
| CVE-2001-0724 | 0.01 | — | 0.12 | Nov 14, 2001 | Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing… | |||
| CVE-2001-0665 | 0.01 | — | 0.12 | Oct 30, 2001 | Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding… | |||
| CVE-2001-0339 | 0.01 | — | 0.15 | Jun 27, 2001 | Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability." | |||
| CVE-2001-1450 | 0.01 | — | 0.07 | May 11, 2001 | Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./". | |||
| CVE-2001-0154 | 0.01 | — | 0.11 | May 3, 2001 | HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. | |||
| CVE-2001-0092 | 0.01 | — | 0.12 | Feb 16, 2001 | A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability. | |||
| CVE-2000-0982 | 0.01 | — | 0.13 | Dec 19, 2000 | Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability. | |||
| CVE-2000-0768 | 0.01 | — | 0.10 | Oct 20, 2000 | A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability. | |||
| CVE-2000-0503 | 0.01 | — | 0.09 | Jun 6, 2000 | The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event. | |||
| CVE-2000-0464 | 0.01 | — | 0.13 | May 17, 2000 | Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability. | |||
| CVE-2000-0439 | 0.01 | — | 0.06 | May 11, 2000 | Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. |
- CVE-2002-0101Mar 25, 2002risk 0.01cvss —epss 0.12
Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.
- CVE-2002-0052Mar 8, 2002risk 0.01cvss —epss 0.18
Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.
- CVE-2002-0025Mar 8, 2002risk 0.01cvss —epss 0.14
Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, which allows remote attackers to modify which application is used to process a document.
- CVE-2002-0026Mar 8, 2002risk 0.01cvss —epss 0.13
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.
- CVE-2002-0077Jan 13, 2002risk 0.01cvss —epss 0.11
Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the…
- CVE-2001-1539Dec 31, 2001risk 0.01cvss —epss 0.14
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem.
- CVE-2001-0807Dec 6, 2001risk 0.01cvss —epss 0.07
Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.
- CVE-2001-0904Nov 20, 2001risk 0.01cvss —epss 0.07
Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.
- CVE-2001-0723Nov 14, 2001risk 0.01cvss —epss 0.11
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."
- CVE-2001-0724Nov 14, 2001risk 0.01cvss —epss 0.12
Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing…
- CVE-2001-0665Oct 30, 2001risk 0.01cvss —epss 0.12
Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding…
- CVE-2001-0339Jun 27, 2001risk 0.01cvss —epss 0.15
Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."
- CVE-2001-1450May 11, 2001risk 0.01cvss —epss 0.07
Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".
- CVE-2001-0154May 3, 2001risk 0.01cvss —epss 0.11
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
- CVE-2001-0092Feb 16, 2001risk 0.01cvss —epss 0.12
A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.
- CVE-2000-0982Dec 19, 2000risk 0.01cvss —epss 0.13
Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.
- CVE-2000-0768Oct 20, 2000risk 0.01cvss —epss 0.10
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
- CVE-2000-0503Jun 6, 2000risk 0.01cvss —epss 0.09
The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.
- CVE-2000-0464May 17, 2000risk 0.01cvss —epss 0.13
Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.
- CVE-2000-0439May 11, 2000risk 0.01cvss —epss 0.06
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.
Page 82 of 87