Vulnerabilities > Microsoft > Internet Explorer > 5.5

DATE CVE VULNERABILITY TITLE RISK
2004-12-23 CVE-2004-0842 Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
network
low complexity
microsoft avaya
7.5
2004-12-23 CVE-2004-0841 Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
network
low complexity
microsoft avaya
5.0
2004-11-03 CVE-2004-0845 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
network
low complexity
microsoft
6.4
2004-11-03 CVE-2004-0843 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
network
low complexity
microsoft
5.0
2004-11-03 CVE-2004-0216 Unspecified vulnerability in Microsoft IE and Internet Explorer
Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.
network
low complexity
microsoft
critical
10.0
2004-08-18 CVE-2004-0839 Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
network
low complexity
microsoft avaya nortel
5.0
2004-08-06 CVE-2004-0549 Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0
The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.
network
low complexity
microsoft
critical
10.0
2004-08-06 CVE-2004-0526 Unspecified vulnerability in Microsoft products
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
network
low complexity
microsoft
5.0
2004-07-27 CVE-2004-0719 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
network
low complexity
microsoft
7.5
2004-07-27 CVE-2004-0566 Unspecified vulnerability in Microsoft Internet Explorer 5.0/5.0.1/5.5
Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.
network
low complexity
microsoft
7.5