CVE-2010-0267
- EPSS 66.17%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corrupti...
CVE-2010-0488
- EPSS 15.55%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding ...
CVE-2010-0489
- EPSS 35.42%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."
CVE-2010-0490
- EPSS 62.1%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...
CVE-2010-0491
- EPSS 62.43%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object M...
CVE-2010-0492
- EPSS 62.85%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, ...
CVE-2010-0494
- EPSS 50.18%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the cl...
CVE-2010-0805
- EPSS 87.69%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the...
CVE-2010-0807
- EPSS 62.1%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
CVE-2010-1098
- EPSS 27.24%
- Veröffentlicht 24.03.2010 22:44:14
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO h...