Vulnerabilities > Microsoft > Internet Explorer > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-08-15 CVE-2007-4356 Unspecified vulnerability in Microsoft Internet Explorer 6/7
Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during an FTP session, which allows context-dependent attackers to obtain sensitive information by reading the HTML source, as demonstrated by a (1) .htm, (2) .html, or (3) .mht file.
network
microsoft
critical
9.3
2007-08-14 CVE-2007-1749 Unspecified vulnerability in Microsoft Internet Explorer 5.01/6/7
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.
network
microsoft
critical
9.3
2007-08-14 CVE-2007-2216 Configuration vulnerability in Microsoft Internet Explorer 5.01/6/7
The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka "ActiveX Object Vulnerability."
network
microsoft CWE-16
critical
9.3
2007-08-14 CVE-2007-3041 Unspecified vulnerability in Microsoft Internet Explorer 5.01/6/7
Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and 7 allows remote attackers to execute arbitrary code via unknown vectors related to Microsoft Visual Basic 6 objects and memory corruption, aka "ActiveX Object Memory Corruption Vulnerability."
network
microsoft
critical
9.3
2007-07-17 CVE-2007-3826 Unspecified vulnerability in Microsoft Internet Explorer 7
Microsoft Internet Explorer 7 on Windows XP SP2 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via repeated document.open function calls after a user requests a new page, but before the onBeforeUnload function is called.
network
microsoft
critical
9.3
2007-06-21 CVE-2007-3341 Unspecified vulnerability in Microsoft Internet Explorer 5/6.0/7.0
Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217.
network
low complexity
microsoft
critical
10.0
2007-06-12 CVE-2007-0218 Code Injection vulnerability in Microsoft Internet Explorer 5.01/6/7.0
Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.
network
microsoft CWE-94
critical
9.3
2007-06-12 CVE-2007-1750 Unspecified vulnerability in Microsoft Internet Explorer 5.01/6/7.0
Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.
network
microsoft
critical
9.3
2007-06-12 CVE-2007-1751 Use of Uninitialized Resource vulnerability in Microsoft Internet Explorer 5.01/6/7.0
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."
network
microsoft CWE-908
critical
9.3
2007-06-12 CVE-2007-2222 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Internet Explorer 5.01/6/7.0
Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.
network
microsoft CWE-119
critical
9.3