Microsoft

Ie

201 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 12.39%
  • Veröffentlicht 09.03.2012 11:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn...

Exploit
  • EPSS 10.86%
  • Veröffentlicht 07.12.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information a...

Exploit
  • EPSS 22.21%
  • Veröffentlicht 07.12.2011 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTM...

  • EPSS 33.88%
  • Veröffentlicht 03.06.2011 17:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC ...

  • EPSS 34.76%
  • Veröffentlicht 03.06.2011 17:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: U...

Exploit
  • EPSS 16.28%
  • Veröffentlicht 01.06.2010 20:30:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.

Exploit
  • EPSS 13.65%
  • Veröffentlicht 20.05.2010 17:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive applicati...

Exploit
  • EPSS 30.08%
  • Veröffentlicht 22.07.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later repo...

  • EPSS 16.72%
  • Veröffentlicht 10.07.2009 21:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.

  • EPSS 2.95%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a vali...