Show filters
44 Total Results
Displaying 21-30 of 44
Sort by:
Attacker Value
Unknown
CVE-2007-5347
Disclosure Date: December 12, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2007-4848
Disclosure Date: September 12, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.
0
Attacker Value
Unknown
CVE-2007-3550
Disclosure Date: July 03, 2007 (last updated November 08, 2023)
Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated
0
Attacker Value
Unknown
CVE-2007-0942
Disclosure Date: May 08, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls," which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.
0
Attacker Value
Unknown
CVE-2007-1765
Disclosure Date: March 30, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.
0
Attacker Value
Unknown
CVE-2007-1499
Disclosure Date: March 17, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability."
0
Attacker Value
Unknown
CVE-2006-7065
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
0
Attacker Value
Unknown
CVE-2007-1114
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
0
Attacker Value
Unknown
CVE-2007-1091
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
0
Attacker Value
Unknown
CVE-2007-0219
Disclosure Date: February 13, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.
0