CVE-2000-0519
- EPSS 2.19%
- Veröffentlicht 05.06.2000 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabili...
CVE-2000-0160
- EPSS 10.33%
- Veröffentlicht 21.02.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
CVE-2000-0162
- EPSS 1.48%
- Veröffentlicht 18.02.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
- EPSS 24.15%
- Veröffentlicht 04.01.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in Internet Explorer 4.0 via EMBED tag.
CVE-2000-0028
- EPSS 21.84%
- Veröffentlicht 23.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
- EPSS 19.71%
- Veröffentlicht 22.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
CVE-1999-0989
- EPSS 6.21%
- Veröffentlicht 06.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.
CVE-1999-0839
- EPSS 0.78%
- Veröffentlicht 29.11.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.
CVE-2000-0329
- EPSS 8.05%
- Veröffentlicht 11.11.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
CVE-1999-0827
- EPSS 0.88%
- Veröffentlicht 01.11.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.