Show filters
304 Total Results
Displaying 201-210 of 304
Sort by:
Attacker Value
Unknown
CVE-2002-1185
Disclosure Date: December 11, 2002 (last updated February 22, 2025)
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
0
Attacker Value
Unknown
CVE-2002-1142
Disclosure Date: November 29, 2002 (last updated February 22, 2025)
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
0
Attacker Value
Unknown
CVE-2002-1217
Disclosure Date: October 28, 2002 (last updated February 22, 2025)
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.
0
Attacker Value
Unknown
CVE-2002-0648
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.
0
Attacker Value
Unknown
CVE-2002-0647
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".
0
Attacker Value
Unknown
CVE-2002-0980
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.
0
Attacker Value
Unknown
CVE-2002-0691
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01 and 5.5 allows remote attackers to execute scripts in the Local Computer zone via a URL that references a local HTML resource file, a variant of "Cross-Site Scripting in Local HTML Resource" as identified by CAN-2002-0189.
0
Attacker Value
Unknown
CVE-2002-0723
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."
0
Attacker Value
Unknown
CVE-2002-0976
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.
0
Attacker Value
Unknown
CVE-2002-0722
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."
0