Show filters
68 Total Results
Displaying 61-68 of 68
Sort by:
Attacker Value
Unknown
CVE-2006-2766
Disclosure Date: June 02, 2006 (last updated October 04, 2023)
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
0
Attacker Value
Unknown
CVE-2006-2094
Disclosure Date: April 29, 2006 (last updated October 04, 2023)
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
0
Attacker Value
Unknown
CVE-2006-1359
Disclosure Date: March 23, 2006 (last updated February 22, 2025)
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
0
Attacker Value
Unknown
CVE-2005-4810
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
0
Attacker Value
Unknown
CVE-2005-4842
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
0
Attacker Value
Unknown
CVE-2005-4843
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
0
Attacker Value
Unknown
CVE-2005-4841
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
0
Attacker Value
Unknown
CVE-2004-1155
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.
0