Show filters
78 Total Results
Displaying 71-78 of 78
Sort by:
Attacker Value
Unknown
CVE-2002-0193
Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.
0
Attacker Value
Unknown
CVE-2002-0078
Disclosure Date: March 29, 2002 (last updated February 22, 2025)
The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.
0
Attacker Value
Unknown
CVE-2002-0052
Disclosure Date: March 08, 2002 (last updated February 22, 2025)
Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.
0
Attacker Value
Unknown
CVE-2002-0077
Disclosure Date: January 13, 2002 (last updated February 22, 2025)
Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.
0
Attacker Value
Unknown
CVE-2001-0712
Disclosure Date: October 30, 2001 (last updated February 22, 2025)
The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.
0
Attacker Value
Unknown
CVE-2001-1450
Disclosure Date: May 11, 2001 (last updated February 22, 2025)
Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".
0
Attacker Value
Unknown
CVE-2000-0519
Disclosure Date: June 05, 2000 (last updated February 22, 2025)
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
0
Attacker Value
Unknown
CVE-2000-0518
Disclosure Date: June 05, 2000 (last updated February 22, 2025)
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.
0