CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
486 | CVE-1999-0488 | Candidate | Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. | Modified (19991205-01) | ACCEPT(2) Baker, Landfield | MODIFY(2) Frech, Wall | NOOP(2) Christey, Ozancin | Frech> XF:ie-mshtml-crossframe | Wall> (source: MSKB:Q168485) | Christey> CVE-1999-0469 appears to be a duplicate; prefer this one over | that one, since this one has an MS advisory. Confirm with | Microsoft that these are really duplicates. | | Also review CVE-1999-0487, which appears to be a similar | bug. | View |
1090 | CVE-1999-1110 | Candidate | Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. | Proposed (20010912) | ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(2) Cole, Foat | Frech> XF:ie-mediaplayer-activex(7800) | View |
3613 | CVE-2001-0807 | Candidate | Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client"s hard drive via a SCRIPT tag with a SRC value that points to the text file. | Modified (20020226-01) | ACCEPT(3) Baker, Cole, Prosser | MODIFY(1) Frech | NOOP(3) Armstrong, Bishop, Foat | REVIEWING(2) Christey, Wall | Frech> XF:ie-local-file-disclosure(6688) | Prosser> Legacy product, users should have updated. | Courtesy of Microsoft Security Response Center <secure@microsoft.com>: | | IE 5 is no longer supported - so unless this repro"s on 5.01 or 5.5, we wouldn"t consider doing anything for this. | Christey> ADDREF BID:2836 | URL:http://www.securityfocus.com/bid/2836 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
4023 | CVE-2001-1219 | Candidate | Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location. | Proposed (20020315) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(2) Cole, Foat | REJECT(1) Ziese | REVIEWING(1) Wall | Frech> XF:ie-javascript-selflocation-dos(9122) | View |
5367 | CVE-2002-0979 | Candidate | The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code. | Modified (20050610) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall | Frech> XF:ie-javalogging-code-execution(9886) | View |
Page 157 of 20943, showing 5 records out of 104715 total, starting on record 781, ending on 785