Vulnerabilities > Microsoft > Internet Explorer

DATE CVE VULNERABILITY TITLE RISK
2011-11-30 CVE-2011-4345 Cross-Site Scripting vulnerability in Namazu
Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when Internet Explorer 6 or 7 is used, allows remote attackers to inject arbitrary web script or HTML via a cookie.
network
high complexity
namazu microsoft CWE-79
2.6
2011-10-12 CVE-2011-2001 Unspecified vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual Function Table Corruption Remote Code Execution Vulnerability."
network
microsoft
critical
9.3
2011-10-12 CVE-2011-2000 Unspecified vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Body Element Remote Code Execution Vulnerability."
network
microsoft
critical
9.3
2011-10-12 CVE-2011-1999 Unspecified vulnerability in Microsoft Internet Explorer 8
Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."
network
microsoft
critical
9.3
2011-10-12 CVE-2011-1998 Use of Uninitialized Resource vulnerability in Microsoft Internet Explorer 9
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "Jscript9.dll Remote Code Execution Vulnerability."
network
microsoft CWE-908
critical
9.3
2011-10-12 CVE-2011-1997 Improper Input Validation vulnerability in Microsoft Internet Explorer 6
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnLoad Event Remote Code Execution Vulnerability."
network
microsoft CWE-20
critical
9.3
2011-10-12 CVE-2011-1996 Unspecified vulnerability in Microsoft Internet Explorer 6/7/8
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
network
microsoft
critical
9.3
2011-10-12 CVE-2011-1995 Use of Uninitialized Resource vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability."
network
microsoft CWE-908
critical
9.3
2011-10-12 CVE-2011-1993 Unspecified vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Scroll Event Remote Code Execution Vulnerability."
network
microsoft
critical
9.3
2011-08-10 CVE-2011-1964 Use of Uninitialized Resource vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Style Object Memory Corruption Vulnerability."
network
microsoft CWE-908
critical
9.3