CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4581  CVE-2002-0189  Candidate  Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.  Modified (20061101)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Christey  Christey> NOTE: As of 5/20/2002, there is a lack of clarity regarding | the details of this vulnerability and other vulnerabilities | being reported by GreyMagic and Thor Larholm. Additional | details will be added to this candidate if/when they become | available. This candidate is solely for the issue that is | being addressed by Microsoft in MS:MS02-023. Its relationship | with other reported issues is currently unproven. | | This candidate is subject to CD:VAGUE. | Christey> XF:ie-dialog-window-css(8868) | URL:http://www.iss.net/security_center/static/8868.php | Frech> XF:ie-dialog-window-css(8868) | Baker> I agree some of the information appears vague, but seems to be legitimate.  View
4582  CVE-2002-0190  Entry  Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.        View
4583  CVE-2002-0191  Entry  Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability.        View
4584  CVE-2002-0192  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0193, CVE-2002-1564. Reason: This candidate was published with a description that identified a different vulnerability than what was identified in the original authoritative reference. Notes: Consult CVE-2002-0193 or CVE-2002-1564 to find the identifier for the proper issue.  Modified (20050204)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Cox | REJECT(1) Christey  Frech> XF:ie-content-disposition-variant(9085) | Christey> Hrmmm... the MS advisory says this is the "Script within | Cookies Reading Cookies" vulnerability... This description | was also used for CVE-2002-0193. | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> This CAN had the wrong description added to it, which made | it look like a different vulnerability than the one identified | by Microsoft in MS:MS02-023. Therefore this CAN should be | REJECTed.  View
4585  CVE-2002-0193  Entry  Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.        View

Page 917 of 20943, showing 5 records out of 104715 total, starting on record 4581, ending on 4585

Actions