VYPR

Internet Explorer

by Microsoft

CVEs (1,731)

  • CVE-2000-0266Apr 18, 2000
    risk 0.01cvss —epss 0.16

    Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.

  • CVE-2000-0201Mar 1, 2000
    risk 0.01cvss —epss 0.07

    The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.

  • CVE-2000-0160Feb 21, 2000
    risk 0.01cvss —epss 0.09

    The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.

  • CVE-2000-0162Feb 18, 2000
    risk 0.01cvss —epss 0.08

    The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.

  • CVE-1999-1472Dec 31, 1999
    risk 0.01cvss —epss 0.17

    Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.

  • CVE-1999-1473Dec 31, 1999
    risk 0.01cvss —epss 0.07

    When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."

  • CVE-1999-1094Dec 31, 1999
    risk 0.01cvss —epss 0.18

    Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."

  • CVE-1999-1087Dec 31, 1999
    risk 0.01cvss —epss 0.06

    Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by…

  • CVE-1999-1093Dec 31, 1999
    risk 0.01cvss —epss 0.13

    Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.

  • CVE-1999-0858Dec 2, 1999
    risk 0.01cvss —epss 0.14

    Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.

  • CVE-1999-0670Sep 1, 1999
    risk 0.01cvss —epss 0.09

    Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.

  • CVE-1999-0802May 27, 1999
    risk 0.01cvss —epss 0.10

    Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.

  • CVE-1999-0489May 17, 1999
    risk 0.01cvss —epss 0.12

    MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.

  • CVE-1999-1241May 6, 1999
    risk 0.01cvss —epss 0.14

    Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.

  • CVE-1999-0490Apr 21, 1999
    risk 0.01cvss —epss 0.10

    MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.

  • CVE-1999-0488Apr 21, 1999
    risk 0.01cvss —epss 0.12

    Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.

  • CVE-1999-0469Apr 1, 1999
    risk 0.01cvss —epss 0.18

    Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.

  • CVE-1999-0870Oct 1, 1998
    risk 0.01cvss —epss 0.13

    Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.

  • CVE-1999-0871Sep 4, 1998
    risk 0.01cvss —epss 0.12

    Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.

  • CVE-1999-1447Jul 28, 1998
    risk 0.01cvss —epss 0.13

    Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.

Page 83 of 87