CVE-2007-1094
- EPSS 34.74%
- Veröffentlicht 26.02.2007 17:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.
CVE-2007-1091
- EPSS 49.66%
- Veröffentlicht 26.02.2007 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
- EPSS 30.08%
- Veröffentlicht 23.02.2007 03:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a frameset with only one frame that calls resizeTo with certain arguments. NOTE: this issue might be related to CVE-2006-3637.
- EPSS 17.81%
- Veröffentlicht 23.02.2007 03:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll.
- EPSS 65.45%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue th...
CVE-2006-4697
- EPSS 59.02%
- Veröffentlicht 13.02.2007 22:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.
- EPSS 79.78%
- Veröffentlicht 13.02.2007 22:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, wh...
CVE-2007-0612
- EPSS 53.87%
- Veröffentlicht 31.01.2007 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties...
CVE-2006-6956
- EPSS 12.07%
- Veröffentlicht 29.01.2007 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
CVE-2007-0024
- EPSS 45.82%
- Veröffentlicht 09.01.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted ...