CVE-2012-1545
- EPSS 12.39%
- Published 09.03.2012 11:55:01
- Last modified 11.04.2025 00:51:21
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn...
- EPSS 10.86%
- Published 07.12.2011 19:55:01
- Last modified 11.04.2025 00:51:21
The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information a...
CVE-2002-2435
- EPSS 22.21%
- Published 07.12.2011 19:55:00
- Last modified 11.04.2025 00:51:21
The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTM...
CVE-2011-2382
- EPSS 33.88%
- Published 03.06.2011 17:55:00
- Last modified 11.04.2025 00:51:21
Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC ...
CVE-2011-2383
- EPSS 34.76%
- Published 03.06.2011 17:55:00
- Last modified 11.04.2025 00:51:21
Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: U...
CVE-2010-2118
- EPSS 16.28%
- Published 01.06.2010 20:30:02
- Last modified 11.04.2025 00:51:21
Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
- EPSS 13.65%
- Published 20.05.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive applicati...
- EPSS 30.08%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later repo...
CVE-2009-2433
- EPSS 16.72%
- Published 10.07.2009 21:00:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
CVE-2009-2069
- EPSS 2.95%
- Published 15.06.2009 19:30:05
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a vali...