Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown

CVE-2006-0799

Disclosure Date: February 19, 2006 (last updated February 22, 2025)
Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL. NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different.
0
Attacker Value
Unknown

CVE-2005-4827

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces. NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks.
0
Attacker Value
Unknown

CVE-2005-2087

Disclosure Date: July 05, 2005 (last updated February 22, 2025)
Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll). NOTE: the researcher says that the vendor could not reproduce this problem.
0
Attacker Value
Unknown

CVE-2005-1211

Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.
0
Attacker Value
Unknown

CVE-2005-1790

Disclosure Date: June 01, 2005 (last updated February 22, 2025)
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2005-0954

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.
0
Attacker Value
Unknown

CVE-2004-0214

Disclosure Date: November 03, 2004 (last updated February 22, 2025)
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
0
Attacker Value
Unknown

CVE-2004-0484

Disclosure Date: July 07, 2004 (last updated February 22, 2025)
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.
0
Attacker Value
Unknown

CVE-2002-0815

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.
0
Attacker Value
Unknown

CVE-2001-1539

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem.
0