CVE-2007-3493
- EPSS 43.02%
- Veröffentlicht 29.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argum...
- EPSS 33.49%
- Veröffentlicht 29.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via the history.length JavaScript variable.
- EPSS 18.76%
- Veröffentlicht 28.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets t...
CVE-2007-3406
- EPSS 29.36%
- Veröffentlicht 26.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or ...
CVE-2006-7206
- EPSS 48.54%
- Veröffentlicht 22.06.2007 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "i...
- EPSS 35.64%
- Veröffentlicht 21.06.2007 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217.
CVE-2007-0218
- EPSS 55.15%
- Veröffentlicht 12.06.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.
CVE-2007-1750
- EPSS 65.91%
- Veröffentlicht 12.06.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.
CVE-2007-1751
- EPSS 57.7%
- Veröffentlicht 12.06.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corrupti...
CVE-2007-2222
- EPSS 67.29%
- Veröffentlicht 12.06.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object tha...