cbcvebase.

Microsoft Ie vulnerabilities

200 known vulnerabilities affecting microsoft/ie.

Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19

Vulnerabilities

Page 2 of 10
CVE-2006-1388P3HIGHCVSS 7.5PoCv6.02006-03-24
CVE-2006-1388 [HIGH] CVE-2006-1388: Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.
nvd
CVE-2006-1188P3HIGHCVSS 7.5PoCv5.1v5.2.3+2 more2006-04-11
CVE-2006-1188 [HIGH] CVE-2006-1188: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTM Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.
nvd
CVE-2003-0344P3HIGHCVSS 7.5PoCv6.02003-06-16
CVE-2003-0344 [HIGH] CVE-2003-0344: Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.
nvd
CVE-2004-1166P3HIGHCVSS 7.5PoCv6.02004-12-31
CVE-2004-1166 [HIGH] CWE-94 CVE-2004-1166: CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
nvd
CVE-2008-2281P3CRITICALCVSS 9.3PoCv8.0b2008-05-18
CVE-2008-2281 [CRITICAL] CVE-2008-2281: Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0 Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.
nvd
CVE-2006-4193P3HIGHCVSS 7.5PoCv6.02006-08-17
CVE-2006-4193 [HIGH] CVE-2006-4193: Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a d Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certa
nvd
CVE-2004-0842P3HIGHCVSS 7.5PoCv6.02004-12-23
CVE-2004-0842 [HIGH] CVE-2004-0842: Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "@;/*" string, possibly due to a missing comment terminator that may c
nvd
CVE-2005-1989P3HIGHCVSS 7.5PoCv62005-08-10
CVE-2005-1989 [HIGH] CVE-2005-1989: Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain infor Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".
nvd
CVE-2003-1328P3HIGHCVSS 7.5PoCv6.02003-02-19
CVE-2003-1328 [HIGH] CVE-2003-1328: The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."
nvd
CVE-2003-0809P3HIGHCVSS 7.5PoCv6.02003-11-17
CVE-2003-0809 [HIGH] CVE-2003-0809: Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server d Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.
nvd
CVE-2002-1254P3HIGHCVSS 7.5PoCv6.02002-12-11
CVE-2002-1254 [HIGH] CVE-2002-1254: Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
nvd
CVE-2005-1988P3MEDIUMCVSS 5.1PoCv62005-08-10
CVE-2005-1988 [MEDIUM] CVE-2005-1988: Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbi Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".
nvd
CVE-2005-0553P3MEDIUMCVSS 5.1PoCv6.02005-05-02
CVE-2005-0553 [MEDIUM] CVE-2005-0553: Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
nvd
CVE-2003-1026P3CRITICALCVSS 9.3PoCv6.02004-01-20
CVE-2003-1026 [CRITICAL] CWE-264 CVE-2003-1026: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javas Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
nvd
CVE-2007-0612P3HIGHCVSS 7.8PoCv5.0_ta3v6.0+1 more2007-01-31
CVE-2007-0612 [HIGH] CVE-2007-0612: Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfi
nvd
CVE-2003-0113P3HIGHCVSS 7.5PoCv6.02003-05-12
CVE-2003-0113 [HIGH] CVE-2003-0113: Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attacke Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.
nvd
CVE-2006-4219P3HIGHCVSS 7.5PoCv6.02006-08-18
CVE-2006-4219 [HIGH] CVE-2006-4219: The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
nvd
CVE-2003-0816P4HIGHCVSS 7.5PoCv6.02004-02-03
CVE-2003-0816 [HIGH] CVE-2003-0816: Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag fo
nvd
CVE-2003-0838P3HIGHCVSS 7.5PoCv6.02003-11-17
CVE-2003-0838 [HIGH] CVE-2003-0838: Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrar Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532,
nvd
CVE-2006-4495P3HIGHCVSS 7.5PoCv6.02006-08-31
CVE-2006-4495 [HIGH] CVE-2006-4495: Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
nvd
Microsoft Ie vulnerabilities | cvebase