Microsoft

Internet Explorer

1637 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 21.69%
  • Published 13.10.2010 19:00:46
  • Last modified 11.04.2025 00:51:21

Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a cra...

  • EPSS 55.4%
  • Published 13.10.2010 19:00:46
  • Last modified 11.04.2025 00:51:21

Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Unini...

  • EPSS 25.4%
  • Published 13.10.2010 19:00:46
  • Last modified 11.04.2025 00:51:21

The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted information by visiting a web page, a...

  • EPSS 54.76%
  • Published 13.10.2010 19:00:46
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitiali...

  • EPSS 53.28%
  • Published 13.10.2010 19:00:46
  • Last modified 11.04.2025 00:51:21

mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Cor...

  • EPSS 23.22%
  • Published 13.10.2010 19:00:46
  • Last modified 11.04.2025 00:51:21

Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information D...

  • EPSS 55.4%
  • Published 13.10.2010 19:00:46
  • Last modified 11.04.2025 00:51:21

Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1...

  • EPSS 40.22%
  • Published 13.10.2010 19:00:03
  • Last modified 11.04.2025 00:51:21

Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, aka "AutoCo...

Exploit
  • EPSS 14.35%
  • Published 08.10.2010 22:00:36
  • Last modified 11.04.2025 00:51:21

The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtai...

Exploit
  • EPSS 43.67%
  • Published 17.09.2010 18:00:03
  • Last modified 11.04.2025 00:51:21

The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows rem...