Page 5 of 48 results (0.007 seconds)

CVSS: 8.8EPSS: 0%CPEs: 3EXPL: 0

31 Dec 1999 — Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page. • http://support.microsoft.com/support/kb/articles/q191/2/00.asp •

CVSS: 9.8EPSS: 20%CPEs: 1EXPL: 0

31 Dec 1999 — Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue." • http://marc.info/?l=bugtraq&m=88480839506155&w=2 •

CVSS: 7.5EPSS: 1%CPEs: 11EXPL: 1

23 Dec 1999 — Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. • https://www.exploit-db.com/exploits/19686 •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 1

08 Dec 1999 — Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." • https://www.exploit-db.com/exploits/19591 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

01 Nov 1999 — By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0827 •

CVSS: 4.3EPSS: 2%CPEs: 7EXPL: 1

01 Dec 1998 — Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. • https://www.exploit-db.com/exploits/19662 •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

01 Jan 1998 — Buffer overflow in Internet Explorer 4.0(1). • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0331 •

CVSS: 4.3EPSS: 21%CPEs: 5EXPL: 0

08 Jul 1997 — JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. • http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html •