CVE-2006-3450
- EPSS 63.79%
- Veröffentlicht 08.08.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain ...
CVE-2006-3451
- EPSS 64.17%
- Veröffentlicht 08.08.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via uns...
CVE-2006-3637
- EPSS 77.25%
- Veröffentlicht 08.08.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML R...
CVE-2006-3638
- EPSS 64.56%
- Veröffentlicht 08.08.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the ...
CVE-2006-3943
- EPSS 38.26%
- Veröffentlicht 31.07.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties.
- EPSS 43.18%
- Veröffentlicht 31.07.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow...
- EPSS 40.67%
- Veröffentlicht 28.07.2006 00:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) ActiveX object, which triggers a null dereference.
CVE-2006-3730
- EPSS 88.44%
- Veröffentlicht 21.07.2006 14:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which ...
- EPSS 30.92%
- Veröffentlicht 18.07.2006 15:47:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow exception) via a DXImageTransform.Microsoft.Gradient ActiveX object with a long (1) StartColorStr or (2) EndColorStr property.
- EPSS 29.85%
- Veröffentlicht 18.07.2006 15:47:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by accessing the object references of a FolderItem ActiveX object, which triggers a null dereference in the security check.