CVE-2002-1688 – Microsoft Internet Explorer 5.5/6.0 - History List Script Injection
https://notcve.org/view.php?id=CVE-2002-1688
The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back button. • https://www.exploit-db.com/exploits/21376 http://online.securityfocus.com/archive/1/267561 http://www.securityfocus.com/bid/4505 https://exchange.xforce.ibmcloud.com/vulnerabilities/8844 •
CVE-2002-1984
https://notcve.org/view.php?id=CVE-2002-1984
Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046". • http://seclists.org/bugtraq/2002/Jun/0303.html http://www.securityfocus.com/bid/5094 •
CVE-2002-1714 – Microsoft Internet Explorer 5/6 - Self-Referential Object Denial of Service
https://notcve.org/view.php?id=CVE-2002-1714
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion. • https://www.exploit-db.com/exploits/21404 http://online.securityfocus.com/archive/1/268776 http://www.securityfocus.com/bid/4564 https://exchange.xforce.ibmcloud.com/vulnerabilities/8904 •
CVE-2002-1186
https://notcve.org/view.php?id=CVE-2002-1186
Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure." • http://archives.neohapsis.com/archives/bugtraq/2002-09/0018.html http://archives.neohapsis.com/archives/bugtraq/2002-09/0030.html http://www.iss.net/security_center/static/10039.php http://www.osvdb.org/7845 http://www.securityfocus.com/bid/5610 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A143 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre. •
CVE-2002-1185
https://notcve.org/view.php?id=CVE-2002-1185
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure." • http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0105.html http://marc.info/?l=bugtraq&m=103970996205091&w=2 http://www.eeye.com/html/Research/Advisories/AD20021211.html http://www.iss.net/security_center/static/10662.php http://www.securityfocus.com/bid/6216 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-066 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A393 https://oval.cisecurity.org/repository/search/definit •