Page 66 of 840 results (0.008 seconds)

CVSS: 10.0EPSS: 95%CPEs: 4EXPL: 1

15 Jun 2004 — The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the wi... • https://www.exploit-db.com/exploits/316 •

CVSS: 6.5EPSS: 4%CPEs: 32EXPL: 2

08 Jun 2004 — Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack. Versiones desconocidas de Internet Explorer y Outlook permiten a atacantes remotos suplantar URL legítimas en la barra de estado mediante etiquetas A HREF con valores "alt" modificados que apuntan al sitio legí... • https://www.exploit-db.com/exploits/24102 •

CVSS: 9.8EPSS: 38%CPEs: 7EXPL: 3

20 May 2004 — Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475. Internet Explorer 5.x y 6.0 permite a atacantes remotos ejecutar programas arbitrarios mediante una URL conteniendo secuencias ".." (punto punto) en un nombre de fichero terminado en "::" ... • https://www.exploit-db.com/exploits/23504 •

CVSS: 6.5EPSS: 4%CPEs: 1EXPL: 1

20 May 2004 — mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference. Vulnerabilidad desconocida en mshtml.dll en Microsoft Internet Explorer permite a usuarios remotos causar una denegación de servicio (caída) mediante cierto documento HTML que enlaza a un documenteo... • https://www.exploit-db.com/exploits/365 •

CVSS: 10.0EPSS: 96%CPEs: 3EXPL: 2

20 Apr 2004 — The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP. Internet Explorer 6.0.2800.1106 sobre Windows XP y posiblemente otras versiones, permite a atacantes remotos suplantar el tipo de un de un fichero mediante un especificador CLSID en el nombre del fich... • http://secunia.com/advisories/10736 •

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

11 Apr 2004 — Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size. • http://marc.info/?l=bugtraq&m=108183130827872&w=2 •

CVSS: 6.5EPSS: 47%CPEs: 6EXPL: 0

18 Mar 2004 — Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name. Microsoft Internet Explorer 6.0, Outlook 2002, y Outlook 2003 permiten a atacantes remotos causar una denegación de servicio (consumición de CPU) si está desactivado "No guardar las páginas cifradas en el disco), mediante un sitio w... • http://marc.info/?l=bugtraq&m=107643134712133&w=2 •

CVSS: 7.5EPSS: 1%CPEs: 10EXPL: 1

16 Mar 2004 — Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. Microsoft Internet Explorer permite a atacantes remotos saltarse las restriciones de cookies pretendidas en una aplicación web mediante secuencias d... • http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html •

CVSS: 5.3EPSS: 29%CPEs: 10EXPL: 3

07 Feb 2004 — Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist. • https://www.exploit-db.com/exploits/23668 •

CVSS: 7.5EPSS: 1%CPEs: 9EXPL: 0

14 Jan 2004 — Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object. Internet Explorer 5.01 hasta la 6 SP1 permite que atacantes remotos se salten restricciones de seguirdad y lean ficheros arbitrarios mediante objetos XML. • http://secunia.com/advisories/10192 •