Show filters
304 Total Results
Displaying 211-220 of 304
Sort by:
Attacker Value
Unknown

CVE-2002-1444

Disclosure Date: August 15, 2002 (last updated February 22, 2025)
The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.
0
Attacker Value
Unknown

CVE-2002-0500

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.
0
Attacker Value
Unknown

CVE-2002-0461

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.
0
Attacker Value
Unknown

CVE-2002-0832

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store information across browser sessions via the userData (storeuserData) feature.
0
Attacker Value
Unknown

CVE-2002-0371

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
0
Attacker Value
Unknown

CVE-2002-0191

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability.
0
Attacker Value
Unknown

CVE-2002-0269

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.
0
Attacker Value
Unknown

CVE-2002-0190

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.
0
Attacker Value
Unknown

CVE-2002-0188

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the second variant of the "Content Disposition" vulnerability.
0
Attacker Value
Unknown

CVE-2002-0193

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.
0