Show filters
141 Total Results
Displaying 31-40 of 141
Sort by:
Attacker Value
Unknown

CVE-2008-4261

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2008-4259

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file with a long name, aka "HTML Objects Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2008-4260

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2008-3477

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
0
Attacker Value
Unknown

CVE-2008-3473

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."
0
Attacker Value
Unknown

CVE-2008-3475

Disclosure Date: October 15, 2008 (last updated February 09, 2024)
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."
Attacker Value
Unknown

CVE-2008-3472

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability."
0
Attacker Value
Unknown

CVE-2008-3474

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability."
0
Attacker Value
Unknown

CVE-2008-3476

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2008-2257

Disclosure Date: August 13, 2008 (last updated October 04, 2023)
Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.
0