CVE-2007-5158
- EPSS 19.54%
- Veröffentlicht 01.10.2007 05:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to ...
CVE-2007-4848
- EPSS 23.08%
- Veröffentlicht 12.09.2007 20:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image r...
CVE-2007-4790
- EPSS 73.68%
- Veröffentlicht 10.09.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to e...
CVE-2007-4478
- EPSS 19.68%
- Veröffentlicht 22.08.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6.0 and 7 allows user-assisted remote attackers to inject arbitrary web script or HTML in the local zone via a URI, when the document at the associated URL is saved to a local fi...
CVE-2007-4356
- EPSS 28.28%
- Veröffentlicht 15.08.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during an FTP session, which allows context-dependent attackers to obtain sensitive information by reading the HTML source, as demonstrated by a (1) .htm, (2)...
CVE-2007-1749
- EPSS 78.27%
- Veröffentlicht 14.08.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer siz...
CVE-2007-0943
- EPSS 62.19%
- Veröffentlicht 14.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.
CVE-2007-2216
- EPSS 68.64%
- Veröffentlicht 14.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a cr...
CVE-2007-3041
- EPSS 55.84%
- Veröffentlicht 14.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and 7 allows remote attackers to execute arbitrary code via unknown vectors related to Microsoft Visual Basic 6 objects and memory corruption, aka "Active...
CVE-2007-4227
- EPSS 13.28%
- Veröffentlicht 08.08.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain JPG file, as demonstrated by something.jpg. NOTE: this issue might be related to CVE-2007-3958.