
CVE-2008-4261
https://notcve.org/view.php?id=CVE-2008-4261
10 Dec 2008 — Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability." El desbordamiento del búfer en región stack de la memoria en Microsoft Internet Explorer versiones 5.01 SP4, 6 SP1 en Windows 200... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=761 • CWE-399: Resource Management Errors •

CVE-2008-4259 – Microsoft Internet Explorer Webdav Request Parsing Heap Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2008-4259
09 Dec 2008 — Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file with a long name, aka "HTML Objects Memory Corruption Vulnerability." Microsoft Internet Explorer versión 7 algunas veces intenta acceder a las ubicaciones de memoria no inicializadas, lo que permite a los atacantes remotos ejecutar código arbitrario por medio de u... • http://www.securityfocus.com/archive/1/499065/100/0/threaded • CWE-399: Resource Management Errors •

CVE-2008-4787 – Microsoft Internet Explorer 6 - ' ' Address Bar URI Spoofing
https://notcve.org/view.php?id=CVE-2008-4787
29 Oct 2008 — Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ticket MSRC7899, a related issue to CVE-2003-1025. Una vulnerabilidad de truncamiento visual en Microsoft Internet Explorer versión 6, permite a los atacantes remotos suplantar la barra de direcciones por medio de una dirección URL con un nombre de host que contie... • https://www.exploit-db.com/exploits/32539 •

CVE-2008-4788
https://notcve.org/view.php?id=CVE-2008-4788
29 Oct 2008 — Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote attackers to spoof the address bar via a URL with a domain name that differs from an important domain name only in these characters, as demonstrated by using exam%A9ple.com to spoof example.com, aka MSRC ticket MSRC7900. Microsoft Internet Explorer 6 omite ciertos caracteres codificados al mostrar la barra de direcciones, lo que permite a un atacante remoto falsear la barra de direcciones... • http://www.securityfocus.com/archive/1/497825/100/0/threaded •

CVE-2008-3472
https://notcve.org/view.php?id=CVE-2008-3472
15 Oct 2008 — Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability." Microsoft Internet Explorer 6 y 7 no determina correctamente el dominio o zona de seguridad original de un script, lo que permite a un atacante remoto eludir la política de seg... • http://marc.info/?l=bugtraq&m=122479227205998&w=2 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-3473
https://notcve.org/view.php?id=CVE-2008-3473
15 Oct 2008 — Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability." Microsoft Internet Explorer v6 y v7 no determina de forma adecuada el dominio o zona de seguridad del origen de la secuencia de comandos web, lo que permite a atacantes remot... • http://marc.info/?l=bugtraq&m=122479227205998&w=2 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-3474
https://notcve.org/view.php?id=CVE-2008-3474
15 Oct 2008 — Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability." Microsoft Internet Explorer 6 y 7 no determina apropiadamente el dominio o zona de seguridad de origen de una secuencia de comandos (script) web, lo cual permite a atacantes remotos evitar polít... • http://marc.info/?l=bugtraq&m=122479227205998&w=2 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2008-3476
https://notcve.org/view.php?id=CVE-2008-3476
15 Oct 2008 — Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulnerability." Microsoft Internet Explorer 5.01 SP4 y 6 no gestiona correctamente los errores asociados con el acceso a memoria no inicializada, lo que permite a atacantes remotos ejecutar código de su elección mediante un documento HTML, también conocido como "HTML ... • http://marc.info/?l=bugtraq&m=122479227205998&w=2 • CWE-399: Resource Management Errors •

CVE-2008-3477
https://notcve.org/view.php?id=CVE-2008-3477
15 Oct 2008 — Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability." Microsoft Excel 2000 SP3, 2002 SP3 y 2003 SP2 y SP3 no valida correctamente los da... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=746 • CWE-399: Resource Management Errors •

CVE-2008-3475 – Microsoft Internet Explorer componentFromPoint Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2008-3475
14 Oct 2008 — Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability." Microsoft Internet Explorer 6 no maneja adecuadamente errores asociados con accesos a un objeto que ha sido (1) inicializado incorrectamente o (2) borrado, lo cual permite a atacantes remotos... • http://ifsec.blogspot.com/2008/10/internet-explorer-6-componentfrompoint.html • CWE-908: Use of Uninitialized Resource •