Microsoft Ie vulnerabilities
200 known vulnerabilities affecting microsoft/ie.
Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19
Vulnerabilities
Page 1 of 10
CVE-2006-3730P2HIGHCVSS 8.8ExploitedPoCv6.02006-07-21
CVE-2006-3730 [HIGH] CWE-94 CVE-2006-3730: Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
nvd
CVE-2004-1050P2CRITICALCVSS 10.0ExploitedPoCv6.02004-12-31
CVE-2004-1050 [CRITICAL] CVE-2004-1050: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
nvd
CVE-2006-4777P2HIGHCVSS 7.6ExploitedPoCv6.02006-09-14
CVE-2006-4777 [HIGH] CVE-2006-4777: Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM obj
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demo
nvd
CVE-2007-1765P2CRITICALCVSS 9.3ExploitedPoCv7.02007-03-30
CVE-2007-1765 [CRITICAL] CVE-2007-1765: Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to exe
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet
nvd
CVE-2007-0024P2CRITICALCVSS 9.3ExploitedPoCv6.02007-01-09
CVE-2007-0024 [CRITICAL] CVE-2007-0024: Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet
Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a
nvd
CVE-2005-0053P2HIGHCVSS 7.5ExploitedPoCv6.02005-05-02
CVE-2005-0053 [HIGH] CVE-2005-0053: Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and dr
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
nvd
CVE-2006-1359P2CRITICALCVSS 9.3ExploitedPoCv6.0v7.02006-03-23
CVE-2006-1359 [CRITICAL] CWE-94 CVE-2006-1359: Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
nvd
CVE-2006-4446P2MEDIUMCVSS 5.0ExploitedPoCv6.02006-08-30
CVE-2006-4446 [MEDIUM] CVE-2006-4446: Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Inte
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.
nvd
CVE-2003-1041P2HIGHCVSS 7.5ExploitedPoCv6v6.02004-06-14
CVE-2003-1041 [HIGH] CVE-2003-1041: Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified d
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
nvd
CVE-2005-2087P2MEDIUMCVSS 5.0ExploitedPoCv5.1v5.2.3+1 more2005-07-05
CVE-2005-2087 [MEDIUM] CWE-399 CVE-2005-2087: Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180
Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JV
nvd
CVE-2004-0841P2MEDIUMCVSS 5.0ExploitedPoCv6.02004-12-23
CVE-2004-0841 [MEDIUM] CVE-2004-0841: Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events tha
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
nvd
CVE-2006-3643P2MEDIUMCVSS 6.0Exploitedv62006-08-09
CVE-2006-3643 [MEDIUM] CWE-79 CVE-2006-3643: Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 S
Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
nvd
CVE-2004-0839P2MEDIUMCVSS 5.0Exploitedv6.02004-08-18
CVE-2004-0839 [MEDIUM] CVE-2004-0839: Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attack
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
nvd
CVE-2007-5347P2MEDIUMCVSS 6.8Exploitedv5.xv6.02007-12-12
CVE-2007-5347 [MEDIUM] CWE-399 CVE-2007-5347: Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "un
Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."
nvd
CVE-2007-0217P3CRITICALCVSS 10.0PoCv6.02007-02-13
CVE-2007-0217 [CRITICAL] CVE-2007-0217: The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attacke
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
nvd
CVE-2002-1142P3HIGHCVSS 7.5PoCv6.02002-11-29
CVE-2002-1142 [HIGH] CVE-2002-1142: Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Comp
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
nvd
CVE-2004-0212P3CRITICALCVSS 10.0PoCv6.02004-08-06
CVE-2004-0212 [CRITICAL] CVE-2004-0212: Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 o
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.
nvd
CVE-2006-1245P3HIGHCVSS 7.5PoCv6.02006-03-17
CVE-2006-1245 [HIGH] CVE-2006-1245: Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versi
Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."
nvd
CVE-2006-1186P3CRITICALCVSS 10.0PoCv5.0.1v5.01+1 more2006-04-11
CVE-2006-1186 [CRITICAL] CVE-2006-1186: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.
nvd
CVE-2006-1185P3HIGHCVSS 7.5PoCv5.01v62006-04-11
CVE-2006-1185 [HIGH] CVE-2006-1185: Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to e
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
nvd
1 / 10Next →