CVE-2008-3173
- EPSS 14.38%
- Veröffentlicht 14.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot character, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-S...
CVE-2008-3023
- EPSS 23.63%
- Veröffentlicht 07.07.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and earlier, and 3.6.3 dev3 and earlier development versions, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a d...
CVE-2008-2947
- EPSS 42.04%
- Veröffentlicht 30.06.2008 22:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.hre...
CVE-2008-2948
- EPSS 43.94%
- Veröffentlicht 30.06.2008 22:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrat...
CVE-2008-2949
- EPSS 40.35%
- Veröffentlicht 30.06.2008 22:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrat...
CVE-2008-2841
- EPSS 31.19%
- Veröffentlicht 24.06.2008 19:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.
CVE-2008-1442
- EPSS 62.85%
- Veröffentlicht 12.06.2008 02:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Object...
CVE-2008-2281
- EPSS 55.92%
- Veröffentlicht 18.05.2008 14:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link con...
CVE-2008-2159
- EPSS 0.84%
- Veröffentlicht 12.05.2008 22:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information.
CVE-2008-1085
- EPSS 44.38%
- Veröffentlicht 08.04.2008 23:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that do...