| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2006-3873 |
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869. Published: September 12, 2006; 7:07:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-4560 |
Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running. Published: September 05, 2006; 8:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-4495 |
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll. Published: August 31, 2006; 6:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-4446 |
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points. Published: August 29, 2006; 9:04:00 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2006-3869 |
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression. Published: August 22, 2006; 9:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-4301 |
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1) DXImageTransform.Microsoft.MaskFilter.1, (2) DXImageTransform.Microsoft.Chroma.1, and (3) DX3DTransform.Microsoft.Shapes.1. Published: August 22, 2006; 9:04:00 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2006-4219 |
The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN. Published: August 18, 2006; 3:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-4193 |
Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files. Published: August 16, 2006; 9:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-3639 |
Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages and possibly execute code via unspecified vectors involving a crafted web page, aka "Source Element Cross-Domain Vulnerability." Published: August 08, 2006; 8:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-3640 |
Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited web pages in other domains or zones, aka "Window Location Information Disclosure Vulnerability." Published: August 08, 2006; 8:04:00 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2006-3643 |
Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability." Published: August 08, 2006; 8:04:00 PM -0400 |
V3.x:(not available) V2.0: 6.0 MEDIUM |
| CVE-2006-3450 |
Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file. Published: August 08, 2006; 7:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-3451 |
Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecified vectors. Published: August 08, 2006; 7:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-3637 |
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability." Published: August 08, 2006; 7:04:00 PM -0400 |
V3.x:(not available) V2.0: 5.1 MEDIUM |
| CVE-2006-3638 |
Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability." Published: August 08, 2006; 7:04:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2006-3943 |
Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties. Published: July 31, 2006; 7:04:00 PM -0400 |
V3.x:(not available) V2.0: 2.6 LOW |
| CVE-2006-3944 |
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference. Published: July 31, 2006; 7:04:00 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2006-3910 |
Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) ActiveX object, which triggers a null dereference. Published: July 27, 2006; 8:04:00 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2006-3915 |
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference. Published: July 27, 2006; 8:04:00 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2006-3897 |
Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property. Published: July 27, 2006; 7:04:00 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |