Vulnerabilities > Microsoft > Internet Explorer

DATE CVE VULNERABILITY TITLE RISK
2008-12-12 CVE-2008-5552 Cross-Site Scripting vulnerability in Microsoft Internet Explorer 8
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value.
network
microsoft CWE-79
4.3
2008-12-12 CVE-2008-5551 Cross-Site Scripting vulnerability in Microsoft Internet Explorer 8
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
network
microsoft CWE-79
4.3
2008-12-12 CVE-2008-5548 Improper Input Validation vulnerability in Virusbuster 4.5.11.0
VirusBuster 4.5.11.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
virusbuster microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5546 Improper Input Validation vulnerability in Virusblokada Vba32 Antivirus 3.12.8.5
VirusBlokAda VBA32 3.12.8.5, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
virusblokada microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5545 Improper Input Validation vulnerability in Trend Micro Trend Micro Antivirus 8.700.0.1004
Trend Micro VSAPI 8.700.0.1004 in Trend Micro AntiVirus, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
trend-micro microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5544 Improper Input Validation vulnerability in Hacksoft the Hacker 6.3.0.9.081/6.3.1.2.174
Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
hacksoft microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5543 Improper Input Validation vulnerability in Symantec Antivirus 10.0
Symantec AntiVirus (SAV) 10, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
symantec microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5542 Improper Input Validation vulnerability in Sunbeltsoftware Vipre 3.1.1633.1/3.1.1832.2
Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
sunbeltsoftware microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5541 Improper Input Validation vulnerability in Sophos Anti-Virus 4.33.0
Sophos Anti-Virus 4.33.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
sophos microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5540 Improper Input Validation vulnerability in Secure Computing Secure web Gateway and Webwasher
Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
secure-computing microsoft CWE-20
critical
9.3