Vulnerabilities > Microsoft > Internet Explorer > 6

DATE CVE VULNERABILITY TITLE RISK
2008-12-12 CVE-2008-5532 Improper Input Validation vulnerability in Ikarus Antivirus T3.1.1.34.0/T3.1.1.45.0
Ikarus Virus Utilities T3.1.1.45.0 and possibly T3.1.1.34.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
ikarus microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5531 Improper Input Validation vulnerability in Fortinet Fortiguard Antivirus 3.113.0.0
Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
fortinet microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5530 Improper Input Validation vulnerability in multiple products
Ewido Security Suite 4.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
avg ewido microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5528 Improper Input Validation vulnerability in Aladdin Esafe 7.0.17.0
Aladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
aladdin microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5527 Improper Input Validation vulnerability in Eset Smart Security 3.0
ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
eset microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5526 Improper Input Validation vulnerability in Drweb Anti-Virus 4.44.0.09170
DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
drweb microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5525 Improper Input Validation vulnerability in Clamav 0.93.1/0.94.1
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
clamav microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5524 Improper Input Validation vulnerability in Quickheal CAT Quickheal 10.00/9.50
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
quickheal microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5523 Improper Input Validation vulnerability in Avast Antivirus 4.8.1281.0
avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
avast microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5522 Improper Input Validation vulnerability in AVG Antivirus 8.0.0.161
AVG Anti-Virus 8.0.0.161, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
avg microsoft CWE-20
critical
9.3