CVE-2008-1086
- EPSS 58.75%
- Published 08.04.2008 23:05:00
- Last modified 09.04.2025 00:30:58
The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, wh...
CVE-2008-1544
- EPSS 51.21%
- Published 28.03.2008 23:44:00
- Last modified 09.04.2025 00:30:58
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers t...
CVE-2008-1545
- EPSS 24.21%
- Published 28.03.2008 23:44:00
- Last modified 09.04.2025 00:30:58
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smugglin...
CVE-2008-1368
- EPSS 23.1%
- Published 18.03.2008 00:44:00
- Last modified 09.04.2025 00:30:58
CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted...
CVE-2008-0076
- EPSS 48.45%
- Published 12.02.2008 23:00:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."
CVE-2008-0077
- EPSS 63.02%
- Published 12.02.2008 23:00:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG e...
CVE-2008-0078
- EPSS 51.55%
- Published 12.02.2008 23:00:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."
CVE-2008-0460
- EPSS 15.66%
- Published 25.01.2008 16:00:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote ...
CVE-2008-0454
- EPSS 41.32%
- Published 25.01.2008 01:00:00
- Last modified 09.04.2025 00:30:58
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via th...
- EPSS 12.54%
- Published 04.01.2008 01:46:00
- Last modified 09.04.2025 00:30:58
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.