<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CompuWorld &#187; IE bugs</title>
	<atom:link href="http://www.nofullstop.com/category/bugs-found/ie-bugs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nofullstop.com</link>
	<description></description>
	<lastBuildDate>Sat, 12 Nov 2011 08:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Microsoft Internet Explorer Multiple Vulnerabilities</title>
		<link>http://www.nofullstop.com/2008/02/20/microsoft-internet-explorer-multiple-vulnerabilities/</link>
		<comments>http://www.nofullstop.com/2008/02/20/microsoft-internet-explorer-multiple-vulnerabilities/#comments</comments>
		<pubDate>Wed, 20 Feb 2008 11:00:33 +0000</pubDate>
		<dc:creator>Salman</dc:creator>
				<category><![CDATA[bugs found]]></category>
		<category><![CDATA[IE bugs]]></category>

		<guid isPermaLink="false">http://www.nofullstop.com/2008/02/20/microsoft-internet-explorer-multiple-vulnerabilities/</guid>
		<description><![CDATA[Secunia has released a &#8220;highly critical&#8221; vulnerability for various versions of Internet Explorer. Versions Affected? Microsoft Internet Explorer 5.01 Microsoft Internet Explorer 6.x Microsoft Internet Explorer 7.x How can this vulnerability be exploited? An error in the way HTML with certain layout combinations is interpreted can be exploited to corrupt memory via a specially crafted [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://secunia.com/advisories/28903/" target="_blank">Secunia has released</a> a &#8220;highly critical&#8221; vulnerability for various versions of Internet Explorer.</p>
<p><strong>Versions Affected?</strong></p>
<ul>
<li>Microsoft Internet Explorer 5.01</li>
<li>Microsoft Internet Explorer 6.x</li>
<li>Microsoft Internet Explorer 7.x</li>
</ul>
<p><strong>How can this vulnerability be exploited?<br />
</strong></p>
<ul>
<li> An error in the way HTML with certain layout combinations is interpreted can be exploited to corrupt memory via a specially crafted web page.</li>
<li>An error in the way the &#8220;by&#8221; property of an &#8220;animateMotion&#8221; SVG element is handled can be exploited to corrupt memory via a specially crafted web page assigning other DOM elements to the property.</li>
<li>An error in the argument validation when processing images can be exploited to corrupt memory via a specially crafted web page.</li>
</ul>
<p>Successful exploitation of the vulnerabilities may allow execution of arbitrary code.</p>
<p><strong>Solution</strong></p>
<p>Microsoft has released patches to fight the vulnerability.</p>
<ul>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=1032A039-468B-4C5F-8C1C-5E54C2832E41" target="_blank"> Windows 2000 SP4 and Internet Explorer 5.01 SP4</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=87E66DCE-5060-4814-8754-829B4E190359" target="_blank"> Windows 2000 SP4 and Internet Explorer 6 SP1</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=BB2AA3CB-021F-4890-AB20-2A51F8E17554" target="_blank"> Windows XP SP2 and Internet Explorer 6</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=429B7ED1-FE78-459A-B834-D0F3C69CB703" target="_blank"> Windows Server 2003 SP1/SP2 and Internet Explorer 6</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=5A097F7A-B696-48D0-B13F-337C5FD14E24" target="_blank"> Windows Server 2003 with SP1/SP2 for Itanium-based systems and Internet Explorer 6</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=D4AA293A-6332-4C6C-B128-876F516BD030" target="_blank"> Windows XP SP2 and Internet Explorer 7</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=B72AF1B6-6E23-4005-AEF6-82195B380153" target="_blank"> Windows XP Professional x64 Edition (optionally with SP2) and Internet Explorer 7</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=B2AA6562-881E-4FD6-BE1B-53426A0FF4A9" target="_blank"> Windows Server 2003 SP1/SP2 and Internet Explorer 7</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=4BB99AFC-BE14-4F2E-9570-B7FE09E39131" target="_blank"> Windows Server 2003 x64 Edition (optionally with SP2) and Internet Explorer 7</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=6FA80E2C-5E91-4B33-ACD9-33F156660AE7" target="_blank"> Windows Server 2003 with SP1/SP2 for Itanium-based systems and Internet Explorer 7</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0DE25B98-F443-4874-A06F-4DAAE14C16B0" target="_blank"> Windows Vista and Internet Explorer 7</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=C08EBBE7-639B-4EA2-8304-FAB531930ABF" target="_blank"> Windows Vista x64 Edition and Internet Explorer 7</a></li>
</ul>
<p align="center"><strong>ELSE USE FIREFOX and surf the internet without any problems.</strong></p>
<hr>
<p>© <a href="">CompuWorld</a> - because <b><i>The Genius Inside You Is Still Sleeping.</i></b><br/></p>
	Tags: <a href="http://www.nofullstop.com/tag/ie-bugs/" title="IE bugs" rel="tag">IE bugs</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.nofullstop.com/2008/02/20/microsoft-internet-explorer-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Internet Explorer Hit With Another Vulenrability</title>
		<link>http://www.nofullstop.com/2007/07/16/internet-explorer-hit-with-another-vulenrability/</link>
		<comments>http://www.nofullstop.com/2007/07/16/internet-explorer-hit-with-another-vulenrability/#comments</comments>
		<pubDate>Mon, 16 Jul 2007 17:52:00 +0000</pubDate>
		<dc:creator>Salman</dc:creator>
				<category><![CDATA[bugs found]]></category>
		<category><![CDATA[IE bugs]]></category>

		<guid isPermaLink="false">http://www.nofullstop.com/2007/07/16/internet-explorer-hit-with-another-vulenrability/</guid>
		<description><![CDATA[In midst of attacks from Firefox fans Microsoft Internet Explorer 7 has another vulnerability added to its collection. Security company Secunia has discovered a flaw in IE7 which can be exploited by a malicious website to spoof the address bar, however the company rated the flaw as less critical. The vulnerability is caused due to [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify">In midst of attacks from Firefox fans Microsoft Internet Explorer 7 has another vulnerability added to its collection. Security company <a href="http://secunia.com/advisories/26069/">Secunia</a> has discovered a flaw in IE7 which can be exploited by a malicious website to spoof the address bar, however the company rated the flaw as less critical.</p>
<p style="text-align: justify">The vulnerability is caused due to an error in the handling of the &#8220;document.open()&#8221; method and can be exploited to spoof the address bar if e.g. the user enters a new website manually in the address bar, which is commonly exercised as best practice.</p>
<p style="text-align: justify">Older versions might be also be affected but there are no reports available yet. This vulnerability is extremely important for the Redmond company as its top browser, Internet Explorer 7 is involved into the battle with Firefox and other applications for the leader position of the category.</p>
<p><strong>Solution</strong>:</p>
<p style="text-align: justify">Close all browser windows after visiting untrusted websites.</p>
<hr>
<p>© <a href="">CompuWorld</a> - because <b><i>The Genius Inside You Is Still Sleeping.</i></b><br/></p>
	Tags: <a href="http://www.nofullstop.com/tag/ie-bugs/" title="IE bugs" rel="tag">IE bugs</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.nofullstop.com/2007/07/16/internet-explorer-hit-with-another-vulenrability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scary Vulnerabilities In IE7 And Firefox 2.0</title>
		<link>http://www.nofullstop.com/2007/02/27/scary-vulnerabilities-in-ie7-and-firefox-20/</link>
		<comments>http://www.nofullstop.com/2007/02/27/scary-vulnerabilities-in-ie7-and-firefox-20/#comments</comments>
		<pubDate>Tue, 27 Feb 2007 13:47:00 +0000</pubDate>
		<dc:creator>Salman</dc:creator>
				<category><![CDATA[bugs found]]></category>
		<category><![CDATA[firefox bugs]]></category>
		<category><![CDATA[IE bugs]]></category>

		<guid isPermaLink="false">http://www.nofullstop.com/2007/02/27/scary-vulnerabilities-in-ie7-and-firefox-20/</guid>
		<description><![CDATA[This is scary. I could see my boot.ini file online? Huh. The common vulnerability makes it clear that the flaw in programming could be used for some dangerous works over the Internet. Affected Software Internet Explorer 7 Internet Explorer 6 Internet Explorer 5.01 FireFox 2.0.0.2 FireFox 1.5.0.9 Description For demonstration of vulnerability in IE7 click [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify"><img src="http://www.nofullstop.com/blog/images/ie_vs_firefox.jpg" alt="" width="143" height="107" align="left" />This is scary. I could see my boot.ini file online? Huh. The common vulnerability makes it clear that the flaw in programming could be used for some dangerous works over the Internet.</p>
<p><span style="font-weight: bold">Affected Software<br />
</span>Internet Explorer 7<br />
Internet Explorer 6<br />
Internet Explorer 5.01<br />
FireFox 2.0.0.2<br />
FireFox 1.5.0.9</p>
<p><span style="font-weight: bold">Description<br />
</span></p>
<p style="text-align: justify">For demonstration of vulnerability in IE7 click <a href="http://lcamtuf.coredump.cx/focusbug/ieversion.html">here</a>. For FireFox click <a href="http://lcamtuf.coredump.cx/focusbug/ffversion.html">here</a>. This is a must see for all of the Internet users around. Using the vulnerability some diverted keystrokes which you hit to enter forms on a web page could be used to enter commands over the Internet to see your boot.ini. And this could just be the beginning.</p>
<blockquote>
<p style="text-align: justify">&#8220;Both examples are Windows-specific, and require C:BOOT.INI to exist and be readable by users. The attack itself is not limited to a particular operating system, but I decided to provide a demonstration for most popular desktop OS &#8211; *nix versions that access /etc/hosts or /etc/passwd are easy to develop,”  Zalewski, one who found the vulnerability, stated.“In all modern browsers,  form fields (used to upload user-specified files to a remote server) enjoy some added protection meant to prevent scripts from arbitrarily choosing local files to be sent, and automatically submitting the form without user knowledge. For example, “.value” parameter cannot be set or changed, and any changes to .type reset the contents of the field,” added Michal Zalewski.</p>
</blockquote>
<p style="text-align: justify"><span style="font-weight: bold">Workaround Available<br />
</span> User interaction is a must if both vulnerabilities are to be successfully exploited. In this context, the user would have to enter text in malformed areas on a web page, either from IE or FireFox.  Zalewski explained that the keyboard input in unrelated locations can be selectively geared toward input fields by the attacker.</p>
<p style="text-align: justify">No real workaround looks to be available currently but we will keep you updated with the latest news.</p>
<p style="text-align: justify">Microsoft on one side was shouting that there IE7 is free of vulnerabilities while FireFox was busy releasing patches this month. Now this kick will surely add to there wounds. Let us wait and see how they react.</p>
<p><!-- AddThis Bookmark Button BEGIN --><span style="font-size: 78%"><span style="font-weight: bold">Source: </span><a href="http://news.softpedia.com/news/IE7-and-Firefox-2-0-Share-Vulnerabilities-47439.shtml">Softpedia</a><br />
</span></p>
<hr>
<p>© <a href="">CompuWorld</a> - because <b><i>The Genius Inside You Is Still Sleeping.</i></b><br/></p>
	Tags: <a href="http://www.nofullstop.com/tag/firefox-bugs/" title="firefox bugs" rel="tag">firefox bugs</a>, <a href="http://www.nofullstop.com/tag/ie-bugs/" title="IE bugs" rel="tag">IE bugs</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.nofullstop.com/2007/02/27/scary-vulnerabilities-in-ie7-and-firefox-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

