Microsoft

Internet Explorer

1637 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 63.1%
  • Published 08.05.2007 23:19:00
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corrupt...

  • EPSS 59.13%
  • Published 08.05.2007 23:19:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the fir...

  • EPSS 55.36%
  • Published 08.05.2007 23:19:00
  • Last modified 09.04.2025 00:30:58

Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of...

  • EPSS 76.03%
  • Published 08.05.2007 23:19:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 o...

Exploit
  • EPSS 38.32%
  • Published 26.04.2007 20:19:00
  • Last modified 09.04.2025 00:30:58

CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows remote attackers to conduct HTTP response splitting attacks via a LF (%0a) in the username attribute.

  • EPSS 1.54%
  • Published 26.04.2007 20:19:00
  • Last modified 09.04.2025 00:30:58

CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.

  • EPSS 27.68%
  • Published 22.04.2007 19:19:00
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

  • EPSS 59.33%
  • Published 30.03.2007 00:19:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing curs...

Exploit
  • EPSS 17.74%
  • Published 02.03.2007 21:18:00
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.

Exploit
  • EPSS 35.64%
  • Published 02.03.2007 21:18:00
  • Last modified 09.04.2025 00:30:58

Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the obje...