Total vulnerabilities in the database
Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the content of the new page, as demonstrated by setInterval functions that set location.href within a try/catch expression, aka the "bait & switch vulnerability" or "Race Condition Cross-Domain Information Disclosure Vulnerability."
Software | From | Fixed in |
---|---|---|
microsoft / windows_2003_server | sp1 | sp1.x |
microsoft / windows_2003_server | sp2 | sp2.x |
microsoft / windows_xp | - | - |
microsoft / internet_explorer | 6 | 6.x |
microsoft / internet_explorer | 7.0 | 7.0.x |
microsoft / windows_2000 | - | - |
microsoft / internet_explorer | 6-sp1 | 6-sp1.x |
microsoft / windows_server_2008 | --sp2 | --sp2.x |
microsoft / windows_vista | - | - |
microsoft / windows_vista | --sp1 | --sp1.x |
microsoft / windows_vista | --sp2 | --sp2.x |