CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1639 | CVE-2000-0061 | Candidate | Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading. | Proposed (20000125) | MODIFY(2) Frech, LeBlanc | NOOP(1) Baker | REJECT(1) Christey | Frech> XF:ie-cross-frame-docs(3901) | LeBlanc> - I"d like to see a KB or bulletin referenced | Christey> This is a duplicate of CVE-2000-0156. The FAQ at | http://www.microsoft.com/technet/security/bulletin/fq00-009.asp. | says "the vulnerability requires Active Scripting" and | "it is possible, under very specific conditions, to violate IE"s | cross-domain security model." Also says "the redirect is made, via | the <IMG SRC> HTML tag" | | Need to copy these references over to CVE-2000-0156. | View |
651 | CVE-1999-0670 | Candidate | Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. | Proposed (19991208) | ACCEPT(3) Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(2) Baker, Cole | Frech> XF:ie-eyedog-bo | Cole> Based on the references and information listed this is the same as | CVE-1999-0669 | Stracener> Add Ref: MSKB Q240308 | Baker> Duplicate | View |
4530 | CVE-2002-0136 | Candidate | Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript. | Modified (20050528) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(2) Cole, Foat | REVIEWING(1) Wall | Frech> XF:ie-html-form-dos(7938) | View |
1350 | CVE-1999-1370 | Candidate | The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:ie-ie5setup-disable-password(7545) | View |
1844 | CVE-2000-0266 | Candidate | Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. | Proposed (20000426) | ACCEPT(5) Baker, Cole, LeBlanc, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:ie-java-crossframe-security | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0028 may | also be a variant. | LeBlanc> MS00-039 | View |
Page 20786 of 20943, showing 5 records out of 104715 total, starting on record 103926, ending on 103930