Microsoft

Internet Explorer

1637 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 13.69%
  • Published 12.12.2008 18:30:03
  • Last modified 09.04.2025 00:30:58

The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header a...

  • EPSS 13.69%
  • Published 12.12.2008 18:30:03
  • Last modified 09.04.2025 00:30:58

The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attack...

  • EPSS 15.47%
  • Published 12.12.2008 18:30:03
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain...

  • EPSS 11.11%
  • Published 12.12.2008 18:30:03
  • Last modified 09.04.2025 00:30:58

The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attack...

Exploit
  • EPSS 82.85%
  • Published 11.12.2008 15:30:00
  • Last modified 09.04.2025 00:30:58

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2)...

  • EPSS 52.72%
  • Published 10.12.2008 14:00:01
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer 5.01 SP4 and 6 SP1 does not properly validate parameters during calls to navigation methods, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Paramet...

  • EPSS 58.73%
  • Published 10.12.2008 14:00:01
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file wit...

  • EPSS 50.95%
  • Published 10.12.2008 14:00:01
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

  • EPSS 64.44%
  • Published 10.12.2008 14:00:01
  • Last modified 09.04.2025 00:30:58

Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers t...

  • EPSS 59.73%
  • Published 12.11.2008 23:30:01
  • Last modified 09.04.2025 00:30:58

Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external...