CVE-2009-2057
- EPSS 11.95%
- Published 15.06.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by m...
CVE-2009-0550
- EPSS 38.59%
- Published 15.04.2009 08:00:00
- Last modified 09.04.2025 00:30:58
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on...
CVE-2009-0552
- EPSS 54.75%
- Published 15.04.2009 08:00:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in me...
CVE-2008-2281
- EPSS 55.92%
- Published 18.05.2008 14:20:00
- Last modified 09.04.2025 00:30:58
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link con...
CVE-2008-1085
- EPSS 44.38%
- Published 08.04.2008 23:05:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that do...
CVE-2008-0076
- EPSS 48.45%
- Published 12.02.2008 23:00:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."
CVE-2008-0078
- EPSS 51.55%
- Published 12.02.2008 23:00:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."
CVE-2007-3902
- EPSS 52.67%
- Published 12.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property o...
CVE-2007-3903
- EPSS 48.18%
- Published 12.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-...
CVE-2007-5344
- EPSS 23.32%
- Published 12.12.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption...