CVE-2010-0490
- EPSS 62.1%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...
CVE-2010-0491
- EPSS 62.43%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object M...
CVE-2010-0492
- EPSS 62.85%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, ...
CVE-2010-0494
- EPSS 50.18%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the cl...
CVE-2010-0805
- EPSS 87.69%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the...
CVE-2010-0807
- EPSS 62.1%
- Veröffentlicht 31.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
CVE-2010-1175
- EPSS 19.23%
- Veröffentlicht 29.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vul...
- EPSS 26.55%
- Veröffentlicht 26.03.2010 20:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted Java...
CVE-2010-1117
- EPSS 39.23%
- Veröffentlicht 25.03.2010 21:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhi...
- EPSS 36.59%
- Veröffentlicht 25.03.2010 21:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competiti...