Vulnerabilities > Microsoft > Internet Explorer

DATE CVE VULNERABILITY TITLE RISK
2008-06-30 CVE-2008-2949 Unspecified vulnerability in Microsoft Internet Explorer 6/7
Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener.
network
microsoft
6.8
2008-06-30 CVE-2008-2948 Unspecified vulnerability in Microsoft Internet Explorer 7/8
Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener.
network
microsoft
6.8
2008-06-30 CVE-2008-2947 Improper Access Control vulnerability in Microsoft Internet Explorer 5.01/6/7
Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors.
network
microsoft CWE-284
6.8
2008-06-24 CVE-2008-2841 Code Injection vulnerability in multiple products
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.
6.8
2008-06-12 CVE-2008-1442 Buffer Errors vulnerability in Microsoft Internet Explorer 6/7
Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Objects Memory Corruption Vulnerability."
network
microsoft CWE-119
critical
9.3
2008-06-03 CVE-2008-2540 Permissions, Privileges, and Access Controls vulnerability in Apple Safari
Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032.
network
apple microsoft CWE-264
critical
9.3
2008-05-18 CVE-2008-2281 Unspecified vulnerability in Microsoft IE and Internet Explorer
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.
network
microsoft
critical
9.3
2008-05-12 CVE-2008-2159 Information Exposure vulnerability in Microsoft Internet Explorer 7
Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information.
local
low complexity
microsoft CWE-200
2.1
2008-04-23 CVE-2007-6255 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method.
network
microsoft CWE-119
critical
9.3
2008-04-17 CVE-2008-1873 Cross-Site Scripting vulnerability in Tru-Zone Nukeet 3.2/3.4
Cross-site scripting (XSS) vulnerability in the private message feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows remote authenticated users to inject arbitrary web script or HTML via a CSS property in the STYLE attribute of a DIV element in the mensaje parameter.
4.3