CVE-2007-5347
- EPSS 46.1%
- Veröffentlicht 12.12.2007 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."
CVE-2007-4848
- EPSS 23.08%
- Veröffentlicht 12.09.2007 20:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image r...
CVE-2007-0943
- EPSS 62.19%
- Veröffentlicht 14.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.
CVE-2007-3550
- EPSS 36.13%
- Veröffentlicht 03.07.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), a...
CVE-2007-0942
- EPSS 59.11%
- Veröffentlicht 08.05.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls,...
CVE-2007-0944
- EPSS 67.08%
- Veröffentlicht 08.05.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute ...
CVE-2007-1765
- EPSS 59.33%
- Veröffentlicht 30.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing curs...
CVE-2007-1499
- EPSS 66.02%
- Veröffentlicht 17.03.2007 10:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the locatio...
- EPSS 17.74%
- Veröffentlicht 02.03.2007 21:18:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
CVE-2007-1114
- EPSS 20.68%
- Veröffentlicht 26.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attac...