Show filters
65 Total Results
Displaying 61-65 of 65
Sort by:
Attacker Value
Unknown

CVE-2002-1670

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Microsoft Windows XP Professional upgrade edition overwrites previously installed patches for Internet Explorer 6.0, leaving Internet Explorer unpatched.
0
Attacker Value
Unknown

CVE-2002-0862

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
0
Attacker Value
Unknown

CVE-2002-0057

Disclosure Date: March 08, 2002 (last updated February 22, 2025)
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
0
Attacker Value
Unknown

CVE-2001-0002

Disclosure Date: July 21, 2001 (last updated February 22, 2025)
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
0
Attacker Value
Unknown

CVE-1999-0967

Disclosure Date: November 01, 1997 (last updated February 22, 2025)
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
0