Vulnerabilities > Microsoft > Internet Explorer > Critical

DATE CVE VULNERABILITY TITLE RISK
2004-01-20 CVE-2003-1027 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."
network
low complexity
microsoft
critical
10.0
2000-01-07 CVE-2000-0061 Unspecified vulnerability in Microsoft Internet Explorer
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.
network
low complexity
microsoft
critical
10.0
1999-05-06 CVE-1999-1241 Unspecified vulnerability in Microsoft Internet Explorer 6.0.2900
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.
network
low complexity
microsoft
critical
10.0
1997-11-01 CVE-1999-0967 Unspecified vulnerability in Microsoft products
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
network
low complexity
microsoft
critical
10.0