Page 81 of 840 results (0.011 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

02 Dec 1999 — Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ247333 • CWE-16: Configuration •

CVSS: 7.5EPSS: 1%CPEs: 2EXPL: 1

17 Nov 1999 — Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. • https://www.exploit-db.com/exploits/19559 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 3

14 Nov 1999 — Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. • https://www.exploit-db.com/exploits/19618 •

CVSS: 8.8EPSS: 1%CPEs: 20EXPL: 1

11 Nov 1999 — A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. • https://www.exploit-db.com/exploits/19603 •

CVSS: 8.8EPSS: 0%CPEs: 3EXPL: 0

01 Nov 1999 — Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-002 •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

01 Nov 1999 — By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0827 •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

31 Oct 1999 — Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. • https://www.exploit-db.com/exploits/19521 •

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0

21 Oct 1999 — The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ240346 • CWE-16: Configuration •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 1

01 Oct 1999 — Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. • https://www.exploit-db.com/exploits/19539 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 3

24 Sep 1999 — Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. • https://www.exploit-db.com/exploits/19528 •