Microsoft

Ie

201 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 19.58%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted w...

Exploit
  • EPSS 66.09%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the com...

Exploit
  • EPSS 11.79%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.

Exploit
  • EPSS 15.09%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFa...

Exploit
  • EPSS 15.8%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.

Exploit
  • EPSS 15.26%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target d...

Exploit
  • EPSS 8.63%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Int...

Exploit
  • EPSS 55.96%
  • Published 23.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerabi...

Exploit
  • EPSS 84.33%
  • Published 23.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based b...

  • EPSS 3.64%
  • Published 23.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it w...