Microsoft Ie vulnerabilities
200 known vulnerabilities affecting microsoft/ie.
Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19
Vulnerabilities
Page 10 of 10
CVE-2010-2118P4MEDIUMCVSS 4.3v8.0.7600.163852010-06-01
CVE-2010-2118 [MEDIUM] CWE-399 CVE-2010-2118: Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a deni
Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
nvd
CVE-2000-0162P4MEDIUMCVSS 5.1v4.0v4.1+2 more2000-02-18
CVE-2000-0162 [MEDIUM] CVE-2000-0162: The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
nvd
CVE-2005-0110P4LOWCVSS 2.6v6.02005-01-14
CVE-2005-0110 [LOW] CVE-2005-0110: Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning di
Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.
nvd
CVE-2006-5805P4MEDIUMCVSS 5.0v7.02006-11-08
CVE-2006-5805 [MEDIUM] CVE-2006-5805: Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure
Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/invalidcert.htm with the target site as an argument, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid.
nvd
CVE-2000-0036P4MEDIUMCVSS 5.0v4.51999-12-22
CVE-2000-0036 [MEDIUM] CVE-2000-0036: Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka t
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
nvd
CVE-2007-1114P4MEDIUMCVSS 4.3v7.02007-02-26
CVE-2007-1114 [MEDIUM] CVE-2007-1114: The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window
The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
nvd
CVE-2004-0979P4MEDIUMCVSS 4.6v6.02004-12-31
CVE-2004-0979 [MEDIUM] CVE-2004-0979: Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files"
Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configuration.
nvd
CVE-2003-1105P4LOWCVSS 2.6v6.02003-12-31
CVE-2003-1105 [LOW] CVE-2003-1105: Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause
Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.
nvd
CVE-2006-3659P4MEDIUMCVSS 5.0v62006-07-18
CVE-2006-3659 [MEDIUM] CVE-2006-3659: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by settin
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the location or URL property of a MHTMLFile ActiveX object.
nvd
CVE-2002-1824P4MEDIUMCVSS 5.0v6.02002-12-31
CVE-2002-1824 [MEDIUM] CVE-2002-1824: Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain
Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack. NOTE: it is not clear whether this poses a vulnerability.
nvd
CVE-2000-0519P4LOWCVSS 2.6v4.0v4.0.1+2 more2000-06-05
CVE-2000-0519 [LOW] CVE-2000-0519: Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establish
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
nvd
CVE-2000-0518P4LOWCVSS 2.6v4.0v4.0.1+3 more2000-06-05
CVE-2000-0518 [LOW] CVE-2000-0518: Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a conne
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.
nvd
CVE-2000-0768P4LOWCVSS 2.6v4.0v5.02000-10-20
CVE-2000-0768 [LOW] CVE-2000-0768: A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
nvd
CVE-2001-1497P4LOWCVSS 2.1v4.0v4.0.1+1 more2001-12-31
CVE-2001-1497 [LOW] CVE-2001-1497: Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanu
Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
nvd
CVE-2006-0753P4LOWCVSS 2.6v62006-02-18
CVE-2006-0753 [LOW] CVE-2006-0753: Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers t
Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
nvd
CVE-2003-1484P4MEDIUMCVSS 4.3v6.02003-12-31
CVE-2003-1484 [MEDIUM] CWE-119 CVE-2003-1484: Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.
nvd
CVE-2004-2219P4LOWCVSS 2.6v6.02004-12-31
CVE-2004-2219 [LOW] CVE-2004-2219: Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishin
Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.
nvd
CVE-2005-1791P4LOWCVSS 2.6v6.02005-05-28
CVE-2005-1791 [LOW] CVE-2005-1791: Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the
Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenario in which an attacker can trigger this behavior, then perhaps this issue should not be included in CVE.
nvd
CVE-1999-0827P4LOWCVSS 2.6v4.01999-11-01
CVE-1999-0827 [LOW] CVE-1999-0827: By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across differe
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
nvd
CVE-2001-1218P4LOWCVSS 2.1v5.02001-12-20
CVE-2001-1218 [LOW] CVE-2001-1218: Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service
Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
nvd
← Previous10 / 10