CVE-2007-0099
- EPSS 56.54%
- Published 08.01.2007 20:28:00
- Last modified 09.04.2025 00:30:58
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in ...
CVE-2006-5579
- EPSS 58.88%
- Published 12.12.2006 20:28:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka "Script Error Handling Memory Corruption Vulnerabi...
CVE-2006-5581
- EPSS 66.19%
- Published 12.12.2006 20:28:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via certain DHTML script functions, such as normalize, and "incorrectly created elements" that trigger memory corruption, aka "DHTML Script F...
- EPSS 14.24%
- Published 06.12.2006 20:28:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of...
- EPSS 45.68%
- Published 06.12.2006 20:28:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.
CVE-2006-4687
- EPSS 62.17%
- Published 14.11.2006 21:07:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulner...
CVE-2006-5884
- EPSS 14.63%
- Published 14.11.2006 21:07:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilit...
CVE-2006-5152
- EPSS 26.46%
- Published 05.10.2006 04:04:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an explicit charset, a related i...
- EPSS 19.16%
- Published 05.10.2006 04:04:00
- Last modified 09.04.2025 00:30:58
wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.
CVE-2006-4868
- EPSS 63.98%
- Published 19.09.2006 19:07:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Marku...