- EPSS 33.38%
- Veröffentlicht 11.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site tha...
CVE-2002-1187
- EPSS 26.56%
- Veröffentlicht 11.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting,...
CVE-2002-1188
- EPSS 16.21%
- Veröffentlicht 11.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security chec...
CVE-2002-1254
- EPSS 72.49%
- Veröffentlicht 11.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification ...
CVE-2002-1142
- EPSS 83.04%
- Veröffentlicht 29.11.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Dat...
CVE-2002-1217
- EPSS 72.57%
- Veröffentlicht 28.10.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Docu...
CVE-2002-0862
- EPSS 12.51%
- Veröffentlicht 04.10.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express f...
CVE-2002-0647
- EPSS 15.52%
- Veröffentlicht 24.09.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".
- EPSS 59.28%
- Veröffentlicht 24.09.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.
CVE-2002-0691
- EPSS 15.06%
- Veröffentlicht 24.09.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 5.01 and 5.5 allows remote attackers to execute scripts in the Local Computer zone via a URL that references a local HTML resource file, a variant of "Cross-Site Scripting in Local HTML Resource" as identified by CAN-2002-...