Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2009-2057

Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
0
Attacker Value
Unknown

CVE-2009-2069

Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.
0
Attacker Value
Unknown

CVE-2007-4041

Disclosure Date: July 27, 2007 (last updated October 04, 2023)
Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
0
Attacker Value
Unknown

CVE-2007-0099

Disclosure Date: January 08, 2007 (last updated October 04, 2023)
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2006-0585

Disclosure Date: February 08, 2006 (last updated October 04, 2023)
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
0
Attacker Value
Unknown

CVE-2004-0867

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
0
Attacker Value
Unknown

CVE-2004-0866

Disclosure Date: September 16, 2004 (last updated February 22, 2025)
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
0
Attacker Value
Unknown

CVE-2002-0057

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
0
Attacker Value
Unknown

CVE-2000-0439

Disclosure Date: May 11, 2000 (last updated February 22, 2025)
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.
0
Attacker Value
Unknown

CVE-1999-0876

Disclosure Date: January 04, 2000 (last updated February 22, 2025)
Buffer overflow in Internet Explorer 4.0 via EMBED tag.
0