Vulnerabilities > Microsoft > IE > 6.0

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-2125 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.
network
low complexity
microsoft
6.4
2002-12-31 CVE-2002-1824 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack.
network
low complexity
microsoft
5.0
2002-12-31 CVE-2002-1714 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
network
low complexity
microsoft
5.0
2002-12-11 CVE-2002-1254 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
network
low complexity
microsoft
7.5
2002-12-11 CVE-2002-1186 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."
network
low complexity
microsoft
5.0
2002-12-11 CVE-2002-1185 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
network
low complexity
microsoft
5.0
2002-11-29 CVE-2002-1142 Unspecified vulnerability in Microsoft Data Access Components, IE and Internet Explorer
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
network
low complexity
microsoft
7.5