Microsoft

Internet Explorer

1637 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 52.67%
  • Veröffentlicht 12.12.2007 00:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property o...

  • EPSS 48.18%
  • Veröffentlicht 12.12.2007 00:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-...

  • EPSS 23.32%
  • Veröffentlicht 12.12.2007 00:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption...

  • EPSS 46.1%
  • Veröffentlicht 12.12.2007 00:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."

  • EPSS 23.23%
  • Veröffentlicht 05.12.2007 11:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three or more components is configured, resolves an unqualified wpad hostname in a second-level domain outside this configured DNS doma...

  • EPSS 10.59%
  • Veröffentlicht 14.10.2007 18:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary .exe files by placing a '?' (question mark) followed by a non-.exe filename after the .exe filename, ...

  • EPSS 82%
  • Veröffentlicht 11.10.2007 00:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as de...

  • EPSS 40.82%
  • Veröffentlicht 09.10.2007 22:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826.

  • EPSS 40.7%
  • Veröffentlicht 09.10.2007 22:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via unspecified vectors involving memory corruption from an unhandled error.

  • EPSS 11.46%
  • Veröffentlicht 08.10.2007 23:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been e...