Show filters
304 Total Results
Displaying 221-230 of 304
Sort by:
Attacker Value
Unknown

CVE-2002-0189

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.
0
Attacker Value
Unknown

CVE-2002-0078

Disclosure Date: March 29, 2002 (last updated February 22, 2025)
The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.
0
Attacker Value
Unknown

CVE-2002-0101

Disclosure Date: March 25, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.
0
Attacker Value
Unknown

CVE-2002-0136

Disclosure Date: March 25, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript.
0
Attacker Value
Unknown

CVE-2002-0025

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, which allows remote attackers to modify which application is used to process a document.
0
Attacker Value
Unknown

CVE-2002-0027

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.
0
Attacker Value
Unknown

CVE-2002-0052

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.
0
Attacker Value
Unknown

CVE-2002-0024

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
File Download box in Internet Explorer 5.01, 5.5 and 6.0 allows an attacker to use the Content-Disposition and Content-Type HTML header fields to modify how the name of the file is displayed, which could trick a user into believing that a file is safe to download.
0
Attacker Value
Unknown

CVE-2002-0022

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.
0
Attacker Value
Unknown

CVE-2002-0023

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.
0