Vulnerabilities > Microsoft > Internet Explorer > Low

DATE CVE VULNERABILITY TITLE RISK
2005-06-01 CVE-2005-1790 Resource Management Errors vulnerability in Microsoft Internet Explorer 6.0.2800.1106/6.0.2900.2180
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."
network
high complexity
microsoft CWE-399
2.6
2004-12-31 CVE-2004-2011 Unspecified vulnerability in Microsoft Internet Explorer 6.0.2600
msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI.
network
high complexity
microsoft
2.6
2004-12-31 CVE-2004-2219 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.
network
high complexity
microsoft
2.6
2004-12-31 CVE-2004-2476 Unspecified vulnerability in Microsoft Internet Explorer 6.0.2800
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.
network
high complexity
microsoft
2.6
2004-11-16 CVE-2004-1331 Unspecified vulnerability in Microsoft IE and Internet Explorer
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
network
high complexity
microsoft
2.6
2004-07-07 CVE-2004-0484 Unspecified vulnerability in Microsoft Internet Explorer 6.0.2900
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.
network
high complexity
microsoft
2.6
2004-04-11 CVE-2004-1922 Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0
Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.
network
high complexity
microsoft
2.6
2003-12-31 CVE-2003-1105 Unspecified vulnerability in Microsoft IE and Internet Explorer
Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.
network
high complexity
microsoft
2.6
2002-08-15 CVE-2002-1444 The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.
network
high complexity
microsoft google
2.6
2001-12-31 CVE-2001-1497 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
local
low complexity
microsoft
2.1