Page 58 of 324 results (0.015 seconds)

CVSS: 2.6EPSS: 1%CPEs: 11EXPL: 1

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. • https://www.exploit-db.com/exploits/19686 https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-2000-0028 •

CVSS: 5.1EPSS: 0%CPEs: 3EXPL: 1

Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." • https://www.exploit-db.com/exploits/19591 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246094 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-050 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ247333 http://www.securityfocus.com/bid/846 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-054 • CWE-16: Configuration •

CVSS: 2.6EPSS: 1%CPEs: 2EXPL: 1

Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. • https://www.exploit-db.com/exploits/19559 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-043 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 3

Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. • https://www.exploit-db.com/exploits/19618 http://www.securityfocus.com/archive/1/34675 http://www.securityfocus.com/bid/793 •