CVE-2004-0484
- EPSS 26.84%
- Veröffentlicht 07.07.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet af...
CVE-2003-1041
- EPSS 70.95%
- Veröffentlicht 14.06.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it ...
CVE-2003-0513
- EPSS 4.64%
- Veröffentlicht 15.04.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside th...
CVE-2004-1922
- EPSS 5.1%
- Veröffentlicht 11.04.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with h...
- EPSS 39.41%
- Veröffentlicht 07.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
CVE-2003-0814
- EPSS 30.72%
- Veröffentlicht 03.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJP...
CVE-2003-0815
- EPSS 13.27%
- Veröffentlicht 03.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or...
CVE-2003-0816
- EPSS 67.22%
- Veröffentlicht 03.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file:...
CVE-2003-0817
- EPSS 12.58%
- Veröffentlicht 03.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.
CVE-2003-0823
- EPSS 30.48%
- Veröffentlicht 03.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.