Vulnerabilities > Microsoft > Internet Explorer > 5.5

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0055 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0054 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."
network
high complexity
microsoft
5.1
2005-05-02 CVE-2005-0053 Unspecified vulnerability in Microsoft products
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
network
low complexity
microsoft
7.5
2005-04-12 CVE-2005-0555 Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0
Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."
network
low complexity
microsoft
7.5
2005-02-09 CVE-2004-0978 Out-Of-Bounds Write vulnerability in Microsoft Internet Explorer 5.01/5.5/6
Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.
network
low complexity
microsoft CWE-787
critical
10.0
2004-12-31 CVE-2004-2383 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus.
network
high complexity
microsoft
5.1
2004-12-31 CVE-2004-2291 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.
network
low complexity
microsoft
7.5
2004-12-31 CVE-2004-2219 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.
network
high complexity
microsoft
2.6
2004-12-31 CVE-2004-1155 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
microsoft
7.5
2004-12-30 CVE-2004-1376 Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0
Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via ..
network
low complexity
microsoft
5.0