Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Microsoft Internet Explorer 6.x
This vulnerability report for Microsoft Internet Explorer 6.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Microsoft Internet Explorer 6.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Microsoft

Product Link View Here (Link to external site)

Affected By 143 Secunia advisories
176 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 16% (23 of 143 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Microsoft Internet Explorer 6.x, with all vendor patches applied, is rated Moderately critical .




35 Secunia Advisories in 2004
Secunia has issued a total of 35 Secunia advisories in 2004 for Microsoft Internet Explorer 6.x. Currently, 20% (7 out of 35) are marked as unpatched with the most severe being rated Moderately critical

More information about the specific Secunia advisories affecting Microsoft Internet Explorer 6.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Internet Explorer DHTML Edit ActiveX Control Cross-Site Scripting
Vendor Patch. Secunia Advisory 1 of 35 in 2004. 143,596 views.
Release Date:
2004-12-16
Secunia Advisory ID:
SA13482
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
System access
Where:
From remote
Short Description:
Paul has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system. [Read More]


Internet Explorer FTP Command Injection Vulnerability
Vendor Patch. Secunia Advisory 2 of 35 in 2004. 35,422 views.
Release Date:
2004-12-09
Secunia Advisory ID:
SA13404
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
Albert Puigsech Galicia has discovered a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to conduct FTP command injection attacks. [Read More]


Microsoft Internet Explorer "sysimage:" Local File Detection Weakness
Vendor Patch. Secunia Advisory 3 of 35 in 2004. 26,275 views.
Release Date:
2004-12-08
Secunia Advisory ID:
SA13396
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Gregory R. Panakkal has discovered a weakness in Internet Explorer, which can be exploited by malicious people to detect the presence of local files. [Read More]


Microsoft Internet Explorer Window Injection Vulnerability
Unpatched. Secunia Advisory 4 of 35 in 2004. 124,353 views.
Release Date:
2004-12-08
Secunia Advisory ID:
SA13251
Solution Status:
Unpatched
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
Secunia Research has reported a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to spoof the content of websites. [Read More]


Microsoft Internet Explorer "Save Picture As" Image Download Spoofing
Unpatched. Secunia Advisory 5 of 35 in 2004. 56,165 views.
Release Date:
2004-11-26
Secunia Advisory ID:
SA13317
Solution Status:
Unpatched
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
cyber flash has discovered a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to trick users into downloading malicious files. [Read More]


Microsoft Internet Explorer Cookie Path Attribute Vulnerability
Partial Fix. Secunia Advisory 6 of 35 in 2004. 33,598 views.
Release Date:
2004-11-17
Secunia Advisory ID:
SA13208
Solution Status:
Partial Fix
Criticality:
Impact:
Hijacking
Where:
From remote
Short Description:
Keigo Yamazaki has reported a vulnerability in Internet Explorer, which potentially can be exploited by malicious people to conduct session fixation attacks. [Read More]


Microsoft Internet Explorer Two Vulnerabilities
Unpatched. Secunia Advisory 7 of 35 in 2004. 59,291 views.
Release Date:
2004-11-17
Secunia Advisory ID:
SA13203
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Spoofing
Where:
From remote
Short Description:
cyber flash has discovered two vulnerabilities in Internet Explorer, which can be exploited by malicious people to bypass a security feature in Microsoft Windows XP SP2 and trick users into downloading malicious files. [Read More]


Internet Explorer Flash/Excel Content Status Bar Spoofing Weakness
Unpatched. Secunia Advisory 8 of 35 in 2004. 34,012 views.
Release Date:
2004-11-10
Secunia Advisory ID:
SA13156
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Roozbeh Afrasiabi has discovered a weakness in Internet Explorer, which can be exploited by malicious people to trick users into visiting a malicious website by obfuscating URLs displayed in the status bar. [Read More]


Microsoft Internet Explorer "res:" URI Handler File Identification Vulnerability
Partial Fix. Secunia Advisory 9 of 35 in 2004. 23,749 views.
Release Date:
2004-11-09
Secunia Advisory ID:
SA13124
Solution Status:
Partial Fix
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Benjamin Tobias Franz has discovered a vulnerability in Internet Explorer, which can be exploited by malicious sites to detect the presence of local files. [Read More]


Internet Explorer HTML Elements Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 10 of 35 in 2004. 187,565 views.
Release Date:
2004-11-02
Secunia Advisory ID:
SA12959
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system. [Read More]


Internet Explorer/Outlook Express Restricted Zone Status Bar Spoofing
Partial Fix. Secunia Advisory 11 of 35 in 2004. 32,510 views.
Release Date:
2004-10-29
Secunia Advisory ID:
SA13015
Solution Status:
Partial Fix
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Benjamin Tobias Franz has discovered a weakness in Internet Explorer, which can be exploited by malicious people to trick users into visiting a malicious website by obfuscating URLs. [Read More]


Microsoft Internet Explorer Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 12 of 35 in 2004. 330,607 views.
Release Date:
2004-10-20
Secunia Advisory ID:
SA12889
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Cross Site Scripting
System access
Where:
From remote
Short Description:
Some vulnerabilities have been discovered in Internet Explorer, which can be exploited by malicious people to compromise a user's system, conduct cross-site/zone scripting and bypass a security feature in Microsoft Windows XP SP2. [Read More]


Internet Explorer Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 13 of 35 in 2004. 39,312 views.
Release Date:
2004-10-12
Secunia Advisory ID:
SA12806
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Internet Explorer, where the most critical can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Internet Explorer Disclosure of Sensitive XML Information
Vendor Patch. Secunia Advisory 14 of 35 in 2004. 23,725 views.
Release Date:
2004-10-09
Secunia Advisory ID:
SA12765
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
Georgi Guninski has reported that a two year old vulnerability has been reintroduced in Microsoft Internet Explorer and can be exploited by malicious people to disclose potentially sensitive information. [Read More]


Internet Explorer Cross-Domain Cookie Injection Vulnerability
Unpatched. Secunia Advisory 15 of 35 in 2004. 26,103 views.
Release Date:
2004-09-18
Secunia Advisory ID:
SA12581
Solution Status:
Unpatched
Criticality:
Impact:
Hijacking
Where:
From remote
Short Description:
WESTPOINT has reported a vulnerability in Internet Explorer, which potentially can be exploited by malicious people to conduct session fixation attacks. [Read More]


Microsoft Multiple Products JPEG Processing Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 16 of 35 in 2004. 56,173 views.
Release Date:
2004-09-14
Secunia Advisory ID:
SA12528
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Nick DeBaggis has reported a vulnerability in multiple Microsoft products, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Internet Explorer Drag and Drop Vulnerability
Vendor Patch. Secunia Advisory 17 of 35 in 2004. 136,089 views.
Release Date:
2004-08-19
Secunia Advisory ID:
SA12321
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
http-equiv has discovered a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system. [Read More]


Internet Explorer Address Bar Spoofing Vulnerability
Partial Fix. Secunia Advisory 18 of 35 in 2004. 102,856 views.
Release Date:
2004-08-16
Secunia Advisory ID:
SA12304
Solution Status:
Partial Fix
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
Liu Die Yu has discovered a vulnerability in Internet Explorer, which potentially can be exploited by malicious people to conduct phishing attacks against a user. [Read More]


Microsoft Internet Explorer Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 19 of 35 in 2004. 32,096 views.
Release Date:
2004-07-30
Secunia Advisory ID:
SA12192
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Microsoft has issued an update for Internet Explorer. This fixes three vulnerabilities, allowing malicious websites to cause a DoS (Denial of Service) or compromise a user's system. [Read More]


Microsoft Internet Explorer Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 20 of 35 in 2004. 186,517 views.
Release Date:
2004-07-13
Secunia Advisory ID:
SA12048
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Spoofing
System access
Where:
From remote
Short Description:
Paul has reported some vulnerabilities in Internet Explorer, which can be exploited by malicious people to bypass security restrictions and potentially compromise a vulnerable system. [Read More]


Internet Explorer "createPopup()" Content Overlay Vulnerability
Partial Fix. Secunia Advisory 21 of 35 in 2004. 10,177 views.
Release Date:
2004-07-13
Secunia Advisory ID:
SA7277
Solution Status:
Partial Fix
Criticality:
Impact:
Security Bypass
Spoofing
System access
Where:
From remote
Short Description:
Paul has reported a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to bypass certain security restrictions and potentially compromise a user's system. [Read More]


Internet Explorer Frame Injection Vulnerability
Vendor Workaround. Secunia Advisory 22 of 35 in 2004. 96,204 views.
Release Date:
2004-06-30
Secunia Advisory ID:
SA11966
Solution Status:
Vendor Workaround
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
Mark Laurence has discovered a 6 year old vulnerability in Internet Explorer, which can be exploited by malicious people to spoof the contents of websites. [Read More]


Internet Explorer File Download Error Message Denial of Service Weakness
Vendor Patch. Secunia Advisory 23 of 35 in 2004. 48,005 views.
Release Date:
2004-06-16
Secunia Advisory ID:
SA11868
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Rafel Ivgi has discovered a weakness in Internet Explorer (IE), allowing malicious people to crash a user's browser. [Read More]


Internet Explorer Security Zone Bypass and Address Bar Spoofing
Vendor Patch. Secunia Advisory 24 of 35 in 2004. 67,489 views.
Release Date:
2004-06-11
Secunia Advisory ID:
SA11830
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Spoofing
Where:
From remote
Short Description:
bitlance winter has reported a vulnerability in Internet Explorer (IE), allowing malicious people to bypass security zones or conduct phishing attacks. [Read More]


Internet Explorer Local Resource Access and Cross-Zone Scripting Vulnerabilities
Vendor Patch. Secunia Advisory 25 of 35 in 2004. 164,801 views.
Release Date:
2004-06-08
Secunia Advisory ID:
SA11793
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Internet Explorer, which in combination with other known issues can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Internet Explorer and Outlook URL Obfuscation Issue
Partial Fix. Secunia Advisory 26 of 35 in 2004. 43,584 views.
Release Date:
2004-05-10
Secunia Advisory ID:
SA11582
Solution Status:
Partial Fix
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
http-equiv has discovered an issue in Microsoft Internet Explorer, Outlook and Outlook Express, allowing malicious people to obfuscate URLs. [Read More]


Windows Explorer / Internet Explorer Long Share Name Buffer Overflow
Vendor Patch. Secunia Advisory 27 of 35 in 2004. 73,399 views.
Release Date:
2004-04-26
Secunia Advisory ID:
SA11482
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Rodrigo Gutierrez has discovered a vulnerability in Windows and Internet Explorer, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Outlook Express MHTML URL Processing Vulnerability
Vendor Patch. Secunia Advisory 28 of 35 in 2004. 44,421 views.
Release Date:
2004-04-13
Secunia Advisory ID:
SA11067
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Outlook Express, which can be exploited by malicious people to compromise a user's system via websites or HTML emails. [Read More]


Internet Explorer/Outlook Express Restricted Zone Status Bar Spoofing
Unpatched. Secunia Advisory 29 of 35 in 2004. 55,021 views.
Release Date:
2004-04-01
Secunia Advisory ID:
SA11273
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
http-equiv has discovered a weakness in Internet Explorer, which potentially can be exploited by malicious people to trick users into visiting a malicious website. [Read More]


Multiple Browser Cookie Path Directory Traversal Vulnerability
Vendor Patch. Secunia Advisory 30 of 35 in 2004. 40,472 views.
Release Date:
2004-03-10
Secunia Advisory ID:
SA9680
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Corsaire has discovered a vulnerability in multiple vendors' browsers, which can be exploited by malicious people to bypass certain cookie restrictions. [Read More]


Internet Explorer Cross Frame Scripting Restriction Bypass
Unpatched. Secunia Advisory 31 of 35 in 2004. 38,365 views.
Release Date:
2004-02-27
Secunia Advisory ID:
SA10996
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Exposure of sensitive information
Where:
From remote
Short Description:
iDEFENSE has reported a vulnerability in Internet Explorer, which can be exploited by malicious people to bypass certain frame scripting restrictions. [Read More]


Internet Explorer File Identification Variant
Partial Fix. Secunia Advisory 32 of 35 in 2004. 31,924 views.
Release Date:
2004-02-09
Secunia Advisory ID:
SA10820
Solution Status:
Partial Fix
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Jelmer has discovered a vulnerability in Internet Explorer, allowing malicious sites to detect the presence of local files. [Read More]


Internet Explorer Travel Log Arbitrary Script Execution Vulnerability
Vendor Patch. Secunia Advisory 33 of 35 in 2004. 29,941 views.
Release Date:
2004-02-02
Secunia Advisory ID:
SA10765
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued patches for Internet Explorer, which fix three vulnerabilities. One of these can be exploited by malicious people to compromise a user's system. [Read More]


Internet Explorer File Download Extension Spoofing
Vendor Patch. Secunia Advisory 34 of 35 in 2004. 139,811 views.
Release Date:
2004-01-28
Secunia Advisory ID:
SA10736
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
http-equiv has identified a vulnerability in Internet Explorer, allowing malicious web sites to spoof the file extension of downloadable files. [Read More]


Internet Explorer showHelp() Restriction Bypass Vulnerability
Vendor Patch. Secunia Advisory 35 of 35 in 2004. 59,211 views.
Release Date:
2004-01-02
Secunia Advisory ID:
SA10523
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Variants of the older showHelp() zone bypass vulnerability have been discovered, which potentially can be exploited to compromise a user's system. [Read More]