CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1639  CVE-2000-0061  Candidate  Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.  Proposed (20000125)  MODIFY(2) Frech, LeBlanc | NOOP(1) Baker | REJECT(1) Christey  Frech> XF:ie-cross-frame-docs(3901) | LeBlanc> - I"d like to see a KB or bulletin referenced | Christey> This is a duplicate of CVE-2000-0156. The FAQ at | http://www.microsoft.com/technet/security/bulletin/fq00-009.asp. | says "the vulnerability requires Active Scripting" and | "it is possible, under very specific conditions, to violate IE"s | cross-domain security model." Also says "the redirect is made, via | the <IMG SRC> HTML tag" | | Need to copy these references over to CVE-2000-0156.  View
651  CVE-1999-0670  Candidate  Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.  Proposed (19991208)  ACCEPT(3) Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(2) Baker, Cole  Frech> XF:ie-eyedog-bo | Cole> Based on the references and information listed this is the same as | CVE-1999-0669 | Stracener> Add Ref: MSKB Q240308 | Baker> Duplicate  View
4530  CVE-2002-0136  Candidate  Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript.  Modified (20050528)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(2) Cole, Foat | REVIEWING(1) Wall  Frech> XF:ie-html-form-dos(7938)  View
1350  CVE-1999-1370  Candidate  The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:ie-ie5setup-disable-password(7545)  View
1844  CVE-2000-0266  Candidate  Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.  Proposed (20000426)  ACCEPT(5) Baker, Cole, LeBlanc, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:ie-java-crossframe-security | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0028 may | also be a variant. | LeBlanc> MS00-039  View

Page 20786 of 20943, showing 5 records out of 104715 total, starting on record 103926, ending on 103930

Actions