Filtered by vendor Microsoft
Subscriptions
Filtered by product Internet Explorer
Subscriptions
Total
1740 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2007-3924 | 2 Microsoft, Netscape | 2 Internet Explorer, Navigator | 2023-11-07 | N/A |
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape; this issue could arise with other protocol handlers in IE. | ||||
CVE-2004-0214 | 1 Microsoft | 5 Internet Explorer, Windows 2000, Windows 98 and 2 more | 2023-11-07 | N/A |
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba. | ||||
CVE-2001-1325 | 1 Microsoft | 2 Internet Explorer, Outlook Express | 2023-11-07 | N/A |
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH). | ||||
CVE-2001-0643 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type. | ||||
CVE-2000-0662 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED). | ||||
CVE-2000-0596 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability. | ||||
CVE-2000-0439 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. | ||||
CVE-2000-0266 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. | ||||
CVE-2000-0160 | 1 Microsoft | 3 Ie, Internet Explorer, Outlook | 2023-11-07 | N/A |
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft. | ||||
CVE-1999-1367 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. | ||||
CVE-1999-0981 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." | ||||
CVE-1999-0917 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. | ||||
CVE-1999-0891 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. | ||||
CVE-1999-0877 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. | ||||
CVE-1999-0876 | 1 Microsoft | 2 Ie, Internet Explorer | 2023-11-07 | N/A |
Buffer overflow in Internet Explorer 4.0 via EMBED tag. | ||||
CVE-1999-0858 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. | ||||
CVE-1999-0802 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. | ||||
CVE-1999-0766 | 1 Microsoft | 2 Internet Explorer, Java Virtual Machine | 2023-11-07 | N/A |
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. | ||||
CVE-1999-0702 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability. | ||||
CVE-1999-0668 | 1 Microsoft | 1 Internet Explorer | 2023-11-07 | N/A |
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. |