Skip to main content

Vendor/product archive

microsoft / internet_explorer CVEs

Beta · best-effort

1,731 CVEs tagged to microsoft / internet_explorer735 Critical, 473 High, 463 Medium, 60 Low, 0 Unrated.

CVE-2006-1191

Published Apr 11, 2006

Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitiv…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1359

Published Mar 23, 2006

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-1016

Published Mar 7, 2006

Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0830

Published Feb 21, 2006

The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that conta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0799

Published Feb 19, 2006

Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitima…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0585

Published Feb 8, 2006

jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0057

Published Jan 27, 2006

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, whi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3240

Published Dec 31, 2005

Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-d…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4810

Published Dec 31, 2005

Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XM…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4841

Published Dec 31, 2005

The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4842

Published Dec 31, 2005

The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4843

Published Dec 31, 2005

The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's C…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4844

Published Dec 31, 2005

The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2829

Published Dec 14, 2005

Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a fil…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2830

Published Dec 14, 2005

Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2831

Published Dec 14, 2005

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embed…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4089

Published Dec 8, 2005

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3312

Published Oct 26, 2005

The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files suc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,476-1,500 of 1,731 CVEsPage 60 of 70