Vulnerabilities > Microsoft > Internet Explorer > 5.0

DATE CVE VULNERABILITY TITLE RISK
2006-10-05 CVE-2006-5162 Unspecified vulnerability in Microsoft Internet Explorer
wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.
network
low complexity
microsoft
5.0
2006-04-29 CVE-2006-2094 Race Condition vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
network
high complexity
microsoft CWE-362
5.1
2006-02-08 CVE-2006-0585 Unspecified vulnerability in Microsoft Internet Explorer
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
network
low complexity
microsoft
5.0
2005-12-31 CVE-2005-4844 Unspecified vulnerability in Microsoft Internet Explorer
The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
network
microsoft
7.1
2004-08-06 CVE-2004-0526 Unspecified vulnerability in Microsoft products
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
network
low complexity
microsoft
5.0
2004-07-27 CVE-2004-0566 Unspecified vulnerability in Microsoft Internet Explorer 5.0/5.0.1/5.5
Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.
network
low complexity
microsoft
7.5
2004-01-20 CVE-2003-1028 Unspecified vulnerability in Microsoft IE and Internet Explorer
The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
network
low complexity
microsoft
5.0
2004-01-20 CVE-2003-1027 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
network
low complexity
microsoft
critical
10.0
2004-01-20 CVE-2003-1026 Permissions, Privileges, and Access Controls vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
network
microsoft CWE-264
critical
9.3
2003-08-18 CVE-2003-0519 Unspecified vulnerability in Microsoft Internet Explorer 5.0/6.0
Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.
network
low complexity
microsoft
5.0