Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2004-1050

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
0
Attacker Value
Unknown

CVE-2004-0841

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
0
Attacker Value
Unknown

CVE-2004-0842

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2004-0839

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
0
Attacker Value
Unknown

CVE-2004-0212

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.
0
Attacker Value
Unknown

CVE-2004-0554

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.
0
Attacker Value
Unknown

CVE-2004-0495

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.
0
Attacker Value
Unknown

CVE-2004-0205

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.
0
Attacker Value
Unknown

CVE-2004-0201

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
0
Attacker Value
Unknown

CVE-2004-0215

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
0