CVE-2016-7282
https://notcve.org/view.php?id=CVE-2016-7282
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability." Vulnerabilidad de XSS en Microsoft Internet Explorer 9 hasta la versión 11 y Microsoft Edge permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través de vectores no especificados, vulnerabilidad también conocida como "Microsoft Browser Information Disclosure Vulnerability." • http://www.securityfocus.com/bid/94724 http://www.securitytracker.com/id/1037444 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-144 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-145 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-7297 – Microsoft Windows JavaScript Array.concat Type Confusion Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2016-7297
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7286, CVE-2016-7288, and CVE-2016-7296. Los motores de secuencias de comandos en Microsoft Edge permiten a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (corrupción de memoria) a través de un sitio web manipulado, vulnerabilidad también conocida como "Scripting Engine Memory Corruption Vulnerability", una vulnerabilidad diferente a CVE-2016-7286, CVE-2016-7288 y CVE-2016-7296. This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the JavaScript Array.concat method. By performing actions in JavaScript an attacker can trigger a type confusion condition. • http://www.securityfocus.com/bid/94751 http://www.securitytracker.com/id/1037444 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-145 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-7198
https://notcve.org/view.php?id=CVE-2016-7198
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7195. Microsoft Internet Explorer 9 hasta la versión 11 y Microsoft Edge permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (corrupción de memoria) a través de un sitio web manipulado, vulnerabilidad también conocida como "Microsoft Browser Memory Corruption Vulnerability", una vulnerabilidad diferente a CVE-2016-7195. • http://www.securityfocus.com/bid/94053 http://www.securitytracker.com/id/1037245 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-142 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-7199
https://notcve.org/view.php?id=CVE-2016-7199
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." Microsoft Internet Explorer 9 hasta la versión 11 y Microsoft Edge permiten a atacantes remotos eludir la Same Origin Policy y obtener información sensible del estado de la ventana a través de un sitio web manipulado, vulnerabilidad también conocida como "Microsoft Browser Information Disclosure Vulnerability". • http://www.securityfocus.com/bid/94057 http://www.securitytracker.com/id/1037245 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-142 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-7202 – Microsoft Internet Explorer Array.splice Memory Corruption Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-7202
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," as demonstrated by the Chakra JavaScript engine, a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243. Los motores de secuencia en Microsoft Internet Explorer 9 hasta la versión 11 y Microsoft Edge permiten a atacantes remotos ejecutar un código arbitrario o provocar una denegación de servicio (corrupción de memoria) a través de un sitio web manipulado, vulnerabilidad también conocida como "Scripting Engine Memory Corruption Vulnerability", como es demostrado por el motor Chakra JavaScript, una vulnerabilidad distinta a CVE-2016-7200, CVE-2016-7201, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242 y CVE-2016-7243. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of the JavaScript method Array.splice. By performing actions in JavaScript an attacker can corrupt the state of a JavaScript array. • https://www.exploit-db.com/exploits/40786 https://www.exploit-db.com/exploits/40793 http://www.securityfocus.com/bid/94042 http://www.securitytracker.com/id/1037245 http://www.zerodayinitiative.com/advisories/ZDI-16-593 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-144 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •