Page 13 of 87 results (0.006 seconds)

CVSS: 5.1EPSS: 0%CPEs: 3EXPL: 1

Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." • https://www.exploit-db.com/exploits/19591 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246094 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-050 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 2.6EPSS: 1%CPEs: 2EXPL: 1

Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. • https://www.exploit-db.com/exploits/19559 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-043 •

CVSS: 5.1EPSS: 1%CPEs: 20EXPL: 1

A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. • https://www.exploit-db.com/exploits/19603 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-048 •

CVSS: 2.6EPSS: 0%CPEs: 11EXPL: 0

By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0827 •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-002 •