Vulnerabilities > Microsoft > Internet Explorer > 7

DATE CVE VULNERABILITY TITLE RISK
2008-12-12 CVE-2008-5528 Improper Input Validation vulnerability in Aladdin Esafe 7.0.17.0
Aladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
aladdin microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5527 Improper Input Validation vulnerability in Eset Smart Security 3.0
ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
eset microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5526 Improper Input Validation vulnerability in Drweb Anti-Virus 4.44.0.09170
DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
drweb microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5525 Improper Input Validation vulnerability in Clamav 0.93.1/0.94.1
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
clamav microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5524 Improper Input Validation vulnerability in Quickheal CAT Quickheal 10.00/9.50
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
quickheal microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5523 Improper Input Validation vulnerability in Avast Antivirus 4.8.1281.0
avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
avast microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5522 Improper Input Validation vulnerability in AVG Antivirus 8.0.0.161
AVG Anti-Virus 8.0.0.161, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
avg microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5521 Improper Input Validation vulnerability in Free-Av Antivir 7.8.1.28/7.9.0.36
Avira AntiVir 7.9.0.36 and possibly 7.8.1.28, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
free-av microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5520 Improper Input Validation vulnerability in Ahnlab V3 Internet Security 2008.12.4.1/2008.9.13.0
AhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
ahnlab microsoft CWE-20
critical
9.3
2008-12-11 CVE-2008-4844 Resource Management Errors vulnerability in Microsoft Internet Explorer 5.01/6/7
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
network
microsoft CWE-399
critical
9.3