Show filters
64 Total Results
Displaying 11-20 of 64
Sort by:
Attacker Value
Unknown

CVE-2006-0585

Disclosure Date: February 08, 2006 (last updated October 04, 2023)
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
0
Attacker Value
Unknown

CVE-2005-4717

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
0
Attacker Value
Unknown

CVE-2004-0526

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
0
Attacker Value
Unknown

CVE-2003-1048

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
Attacker Value
Unknown

CVE-2002-0862

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
0
Attacker Value
Unknown

CVE-2002-0976

Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.
0
Attacker Value
Unknown

CVE-2002-0057

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
0
Attacker Value
Unknown

CVE-2001-1497

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
0
Attacker Value
Unknown

CVE-2001-0322

Disclosure Date: June 02, 2001 (last updated February 22, 2025)
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
0
Attacker Value
Unknown

CVE-2001-0091

Disclosure Date: February 16, 2001 (last updated February 22, 2025)
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.
0