CVE-2008-4787
- EPSS 27.83%
- Veröffentlicht 29.10.2008 15:31:35
- Zuletzt bearbeitet 09.04.2025 00:30:58
Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ti...
- EPSS 16.48%
- Veröffentlicht 29.10.2008 15:31:35
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote attackers to spoof the address bar via a URL with a domain name that differs from an important domain name only in these characte...
CVE-2008-3472
- EPSS 46.05%
- Veröffentlicht 15.10.2008 00:12:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive inf...
CVE-2008-3473
- EPSS 47.04%
- Veröffentlicht 15.10.2008 00:12:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive inf...
CVE-2008-3474
- EPSS 48.92%
- Veröffentlicht 15.10.2008 00:12:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML...
CVE-2008-3475
- EPSS 59.2%
- Veröffentlicht 15.10.2008 00:12:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a craft...
CVE-2008-3476
- EPSS 65.05%
- Veröffentlicht 15.10.2008 00:12:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulner...
CVE-2008-3477
- EPSS 73.25%
- Veröffentlicht 15.10.2008 00:12:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel fil...
- EPSS 30.08%
- Veröffentlicht 02.10.2008 18:18:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
CVE-2008-4127
- EPSS 23.58%
- Veröffentlicht 18.09.2008 17:59:33
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CD...