Microsoft

Internet Explorer

1637 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 30.08%
  • Veröffentlicht 22.07.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later repo...

Exploit
  • EPSS 14.99%
  • Veröffentlicht 20.07.2009 18:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

  • EPSS 16.72%
  • Veröffentlicht 10.07.2009 21:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.

Exploit
  • EPSS 13.29%
  • Veröffentlicht 07.07.2009 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh hea...

  • EPSS 18.53%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by mod...

  • EPSS 2.95%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a vali...

Exploit
  • EPSS 11.95%
  • Veröffentlicht 15.06.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by m...

  • EPSS 55.29%
  • Veröffentlicht 10.06.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers t...

  • EPSS 67.81%
  • Veröffentlicht 10.06.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," ...

  • EPSS 70.97%
  • Veröffentlicht 10.06.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitr...