Vulnerabilities > Microsoft > Internet Explorer

DATE CVE VULNERABILITY TITLE RISK
2008-12-12 CVE-2008-5539 Improper Input Validation vulnerability in Rising-Global Rising Antivirus 20.61.42.00/21.06.31.00
RISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
rising-global microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5538 Improper Input Validation vulnerability in Prevx Prevx1 2
Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
prevx microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5537 Improper Input Validation vulnerability in Pctools Antivirus 4.4.2.0
PC Tools AntiVirus 4.4.2.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
pctools microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5536 Improper Input Validation vulnerability in Pandasecurity Panda Antivirus 9.0.0.4
Panda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
pandasecurity microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5535 Improper Input Validation vulnerability in Norman Antivirus & Antispyware 5.80.02
Norman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
norman microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5534 Improper Input Validation vulnerability in Eset Nod32 Antivirus 3440/3662
ESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
eset microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5533 Improper Input Validation vulnerability in K7Computing Antivirus 7.10.454/7.10.541
K7AntiVirus 7.10.541 and possibly 7.10.454, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
k7computing microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5532 Improper Input Validation vulnerability in Ikarus Antivirus T3.1.1.34.0/T3.1.1.45.0
Ikarus Virus Utilities T3.1.1.45.0 and possibly T3.1.1.34.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
ikarus microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5531 Improper Input Validation vulnerability in Fortinet Fortiguard Antivirus 3.113.0.0
Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
fortinet microsoft CWE-20
critical
9.3
2008-12-12 CVE-2008-5530 Improper Input Validation vulnerability in multiple products
Ewido Security Suite 4.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
avg ewido microsoft CWE-20
critical
9.3