Show filters
68 Total Results
Displaying 31-40 of 68
Sort by:
Attacker Value
Unknown

CVE-2007-4848

Disclosure Date: September 12, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.
0
Attacker Value
Unknown

CVE-2007-3670

Disclosure Date: July 10, 2007 (last updated October 04, 2023)
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."
0
Attacker Value
Unknown

CVE-2007-3550

Disclosure Date: July 03, 2007 (last updated November 08, 2023)
Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated
0
Attacker Value
Unknown

CVE-2007-3497

Disclosure Date: June 29, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via the history.length JavaScript variable.
0
Attacker Value
Unknown

CVE-2007-3493

Disclosure Date: June 29, 2007 (last updated October 04, 2023)
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.
0
Attacker Value
Unknown

CVE-2007-3341

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217.
0
Attacker Value
Unknown

CVE-2007-0218

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.
0
Attacker Value
Unknown

CVE-2007-1751

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2007-1750

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.
0
Attacker Value
Unknown

CVE-2007-2222

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.
0