Vulnerabilities > Microsoft > Internet Explorer

DATE CVE VULNERABILITY TITLE RISK
2005-06-01 CVE-2005-1790 Resource Management Errors vulnerability in Microsoft Internet Explorer 6.0.2800.1106/6.0.2900.2180
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."
network
high complexity
microsoft CWE-399
2.6
2005-05-28 CVE-2005-1829 Unspecified vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.
network
low complexity
microsoft
5.0
2005-05-02 CVE-2005-0954 Unspecified vulnerability in Microsoft Internet Explorer, Windows Explorer and Windows XP
Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.
network
low complexity
microsoft
5.0
2005-05-02 CVE-2005-0554 Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0
Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0553 Unspecified vulnerability in Microsoft IE and Internet Explorer
Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
network
high complexity
microsoft
5.1
2005-05-02 CVE-2005-0500 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.
network
low complexity
microsoft
5.0
2005-05-02 CVE-2005-0056 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
network
high complexity
microsoft
5.1
2005-05-02 CVE-2005-0055 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0054 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."
network
high complexity
microsoft
5.1
2005-05-02 CVE-2005-0053 Unspecified vulnerability in Microsoft products
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
network
low complexity
microsoft
7.5