Vulnerabilities
Vulnerable Software
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
CVSS Score
2.6
EPSS Score
0.218
Published
1999-12-23
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."
CVSS Score
5.1
EPSS Score
0.036
Published
1999-12-08
Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.
CVSS Score
5.0
EPSS Score
0.119
Published
1999-12-02
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
CVSS Score
2.6
EPSS Score
0.228
Published
1999-11-17
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.
CVSS Score
5.0
EPSS Score
0.237
Published
1999-11-14
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.
CVSS Score
7.5
EPSS Score
0.031
Published
1999-11-01
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
CVSS Score
2.6
EPSS Score
0.009
Published
1999-11-01
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.
CVSS Score
5.1
EPSS Score
0.307
Published
1999-10-31
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
CVSS Score
4.3
EPSS Score
0.209
Published
1999-10-01
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.
CVSS Score
5.1
EPSS Score
0.249
Published
1999-09-24


Contact Us

Shodan ® - All rights reserved