Page 11 of 114 results (0.005 seconds)

CVSS: 9.8EPSS: 7%CPEs: 2EXPL: 0

01 Sep 1999 — Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. • http://ciac.llnl.gov/ciac/bulletins/j-064.shtml •

CVSS: 7.5EPSS: 56%CPEs: 1EXPL: 1

01 Sep 1999 — The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. • https://www.exploit-db.com/exploits/19530 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.4EPSS: 8%CPEs: 4EXPL: 2

27 Aug 1999 — Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. • https://www.exploit-db.com/exploits/19471 •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

25 Aug 1999 — Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link. • https://www.exploit-db.com/exploits/19473 •

CVSS: 9.8EPSS: 19%CPEs: 2EXPL: 1

21 Aug 1999 — The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. • https://www.exploit-db.com/exploits/19468 •

CVSS: 9.8EPSS: 17%CPEs: 1EXPL: 0

27 May 1999 — Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ231450 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.5EPSS: 6%CPEs: 2EXPL: 0

27 May 1999 — The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ231452 •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

06 May 1999 — Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. • http://www.pcworld.com/news/article/0%2Caid%2C10842%2C00.asp •

CVSS: 7.5EPSS: 22%CPEs: 2EXPL: 1

01 May 1999 — The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. • https://www.exploit-db.com/exploits/19094 •

CVSS: 8.1EPSS: 3%CPEs: 4EXPL: 0

21 Apr 1999 — Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012 •