Internet Explorer
by Microsoft
CVEs (1,731)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0266 | 0.01 | — | 0.16 | Apr 18, 2000 | Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. | |||
| CVE-2000-0201 | 0.01 | — | 0.07 | Mar 1, 2000 | The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking. | |||
| CVE-2000-0160 | 0.01 | — | 0.09 | Feb 21, 2000 | The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft. | |||
| CVE-2000-0162 | 0.01 | — | 0.08 | Feb 18, 2000 | The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability. | |||
| CVE-1999-1472 | 0.01 | — | 0.17 | Dec 31, 1999 | Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue. | |||
| CVE-1999-1473 | 0.01 | — | 0.07 | Dec 31, 1999 | When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue." | |||
| CVE-1999-1094 | 0.01 | — | 0.18 | Dec 31, 1999 | Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue." | |||
| CVE-1999-1087 | 0.01 | — | 0.06 | Dec 31, 1999 | Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by… | |||
| CVE-1999-1093 | 0.01 | — | 0.13 | Dec 31, 1999 | Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page. | |||
| CVE-1999-0858 | 0.01 | — | 0.14 | Dec 2, 1999 | Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. | |||
| CVE-1999-0670 | 0.01 | — | 0.09 | Sep 1, 1999 | Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. | |||
| CVE-1999-0802 | 0.01 | — | 0.10 | May 27, 1999 | Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. | |||
| CVE-1999-0489 | 0.01 | — | 0.12 | May 17, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | |||
| CVE-1999-1241 | 0.01 | — | 0.14 | May 6, 1999 | Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. | |||
| CVE-1999-0490 | 0.01 | — | 0.10 | Apr 21, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag. | |||
| CVE-1999-0488 | 0.01 | — | 0.12 | Apr 21, 1999 | Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. | |||
| CVE-1999-0469 | 0.01 | — | 0.18 | Apr 1, 1999 | Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. | |||
| CVE-1999-0870 | 0.01 | — | 0.13 | Oct 1, 1998 | Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. | |||
| CVE-1999-0871 | 0.01 | — | 0.12 | Sep 4, 1998 | Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. | |||
| CVE-1999-1447 | 0.01 | — | 0.13 | Jul 28, 1998 | Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. |
- CVE-2000-0266Apr 18, 2000risk 0.01cvss —epss 0.16
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.
- CVE-2000-0201Mar 1, 2000risk 0.01cvss —epss 0.07
The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.
- CVE-2000-0160Feb 21, 2000risk 0.01cvss —epss 0.09
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
- CVE-2000-0162Feb 18, 2000risk 0.01cvss —epss 0.08
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
- CVE-1999-1472Dec 31, 1999risk 0.01cvss —epss 0.17
Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.
- CVE-1999-1473Dec 31, 1999risk 0.01cvss —epss 0.07
When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."
- CVE-1999-1094Dec 31, 1999risk 0.01cvss —epss 0.18
Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."
- CVE-1999-1087Dec 31, 1999risk 0.01cvss —epss 0.06
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by…
- CVE-1999-1093Dec 31, 1999risk 0.01cvss —epss 0.13
Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
- CVE-1999-0858Dec 2, 1999risk 0.01cvss —epss 0.14
Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.
- CVE-1999-0670Sep 1, 1999risk 0.01cvss —epss 0.09
Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.
- CVE-1999-0802May 27, 1999risk 0.01cvss —epss 0.10
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.
- CVE-1999-0489May 17, 1999risk 0.01cvss —epss 0.12
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
- CVE-1999-1241May 6, 1999risk 0.01cvss —epss 0.14
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.
- CVE-1999-0490Apr 21, 1999risk 0.01cvss —epss 0.10
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.
- CVE-1999-0488Apr 21, 1999risk 0.01cvss —epss 0.12
Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.
- CVE-1999-0469Apr 1, 1999risk 0.01cvss —epss 0.18
Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.
- CVE-1999-0870Oct 1, 1998risk 0.01cvss —epss 0.13
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
- CVE-1999-0871Sep 4, 1998risk 0.01cvss —epss 0.12
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.
- CVE-1999-1447Jul 28, 1998risk 0.01cvss —epss 0.13
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.
Page 83 of 87