Vulnerabilities
Vulnerable Software
Microsoft:  >> Ie  Security Vulnerabilities
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
CVSS Score
2.6
EPSS Score
0.163
Published
2000-10-20
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.
CVSS Score
2.6
EPSS Score
0.022
Published
2000-06-05
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
CVSS Score
2.6
EPSS Score
0.022
Published
2000-06-05
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
CVSS Score
7.6
EPSS Score
0.103
Published
2000-02-21
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
CVSS Score
5.1
EPSS Score
0.015
Published
2000-02-18
Buffer overflow in Internet Explorer 4.0 via EMBED tag.
CVSS Score
10.0
EPSS Score
0.241
Published
2000-01-04
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
CVSS Score
2.6
EPSS Score
0.218
Published
1999-12-23
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
CVSS Score
5.0
EPSS Score
0.197
Published
1999-12-22
Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.
CVSS Score
7.5
EPSS Score
0.062
Published
1999-12-06
Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.
CVSS Score
7.2
EPSS Score
0.008
Published
1999-11-29


Contact Us

Shodan ® - All rights reserved