Show filters
65 Total Results
Displaying 11-20 of 65
Sort by:
Attacker Value
Unknown
CVE-2010-0805
Disclosure Date: March 31, 2010 (last updated October 04, 2023)
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0489
Disclosure Date: March 31, 2010 (last updated December 08, 2023)
Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0807
Disclosure Date: March 31, 2010 (last updated December 08, 2023)
Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0488
Disclosure Date: March 31, 2010 (last updated December 08, 2023)
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0492
Disclosure Date: March 31, 2010 (last updated December 08, 2023)
Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0494
Disclosure Date: March 31, 2010 (last updated December 08, 2023)
Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0491
Disclosure Date: March 31, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0267
Disclosure Date: March 31, 2010 (last updated December 08, 2023)
Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0806
Disclosure Date: March 10, 2010 (last updated December 08, 2023)
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2010-0555
Disclosure Date: February 04, 2010 (last updated December 08, 2023)
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka the URLMON sniffing vulnerability, a variant of CVE-2009-1140 and related to CVE-2008-1448.
0