Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown

CVE-2001-1497

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
0
Attacker Value
Unknown

CVE-2000-0982

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.
0
Attacker Value
Unknown

CVE-2000-0596

Disclosure Date: June 27, 2000 (last updated February 22, 2025)
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.
0
Attacker Value
Unknown

CVE-2000-0519

Disclosure Date: June 05, 2000 (last updated February 22, 2025)
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
0
Attacker Value
Unknown

CVE-2000-0518

Disclosure Date: June 05, 2000 (last updated February 22, 2025)
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.
0
Attacker Value
Unknown

CVE-2000-0464

Disclosure Date: May 17, 2000 (last updated February 22, 2025)
Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.
0
Attacker Value
Unknown

CVE-2000-0439

Disclosure Date: May 11, 2000 (last updated February 22, 2025)
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.
0
Attacker Value
Unknown

CVE-2000-0156

Disclosure Date: February 16, 2000 (last updated February 22, 2025)
Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.
0
Attacker Value
Unknown

CVE-2000-0061

Disclosure Date: January 07, 2000 (last updated February 22, 2025)
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.
0
Attacker Value
Unknown

CVE-1999-1093

Disclosure Date: December 31, 1999 (last updated February 22, 2025)
Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
0