Microsoft Ie vulnerabilities
200 known vulnerabilities affecting microsoft/ie.
Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19
Vulnerabilities
Page 3 of 10
CVE-2005-1990P4MEDIUMCVSS 5.1PoCv62005-08-10
CVE-2005-1990 [MEDIUM] CVE-2005-1990: Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (applicatio
Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll,
nvd
CVE-2003-0701P3HIGHCVSS 7.5PoCv6.02003-08-27
CVE-2003-0701 [HIGH] CVE-2003-0701: Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings
Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.
nvd
CVE-2004-2291P3HIGHCVSS 7.5PoCv6.02004-12-31
CVE-2004-2291 [HIGH] CVE-2004-2291: Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code vi
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.
nvd
CVE-2006-0544P3HIGHCVSS 7.5PoCv7.02006-02-04
CVE-2006-0544 [HIGH] CVE-2006-0544: urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cau
urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
nvd
CVE-2006-3637P4MEDIUMCVSS 5.1PoCv62006-08-08
CVE-2006-3637 [MEDIUM] CVE-2006-3637: Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component co
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
nvd
CVE-2007-0942P3CRITICALCVSS 9.3v6.02007-05-08
CVE-2007-0942 [CRITICAL] CVE-2007-0942: Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Wind
Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls," which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.
nvd
CVE-2005-2308P3HIGHCVSS 7.5PoCv6.02005-07-19
CVE-2005-2308 [HIGH] CVE-2005-2308: The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.
nvd
CVE-2004-1104P4HIGHCVSS 7.5PoCv6.02004-12-31
CVE-2004-1104 [HIGH] CVE-2004-1104: Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status
Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that contains a BASE element that points to the legitimate site, followed by an anchor (a) element with an empty "href" attribute, and a FORM whose action points to a malicious URL, and an INPUT submit element that
nvd
CVE-2009-0552P3CRITICALCVSS 9.3v6.02009-04-15
CVE-2009-0552 [CRITICAL] CWE-94 CVE-2009-0552: Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulner
nvd
CVE-2004-0216P3CRITICALCVSS 10.0v62004-11-03
CVE-2004-0216 [CRITICAL] CVE-2004-0216: Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows re
Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.
nvd
CVE-2009-0550P3CRITICALCVSS 9.3v6.02009-04-15
CVE-2009-0550 [CRITICAL] CVE-2009-0550: Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 a
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remot
nvd
CVE-2004-0420P3CRITICALCVSS 10.0v6.02004-07-07
CVE-2004-0420 [CRITICAL] CVE-2004-0420: The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, a
The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.
nvd
CVE-2007-0944P3CRITICALCVSS 9.3v6.02007-05-08
CVE-2007-0944 [CRITICAL] CVE-2007-0944: Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5
Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute arbitrary code by calling deleteCell on a named table row in a named table column, then accessing the column,
nvd
CVE-2007-3902P3CRITICALCVSS 9.3v5.xv6.02007-12-12
CVE-2007-3902 [CRITICAL] CWE-189 CVE-2007-3902: Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Exp
Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2002-0153P4HIGHCVSS 7.5PoCv3.0v3.1+5 more2002-04-22
CVE-2002-0153 [HIGH] CVE-2002-0153: Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke loc
Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.
nvd
CVE-2008-0076P3CRITICALCVSS 9.3v5.01v6+1 more2008-02-12
CVE-2008-0076 [CRITICAL] CWE-94 CVE-2008-0076: Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote at
Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."
nvd
CVE-2008-1085P3CRITICALCVSS 9.3v5.01v6+1 more2008-04-08
CVE-2008-1085 [CRITICAL] CWE-94 CVE-2008-1085: Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows re
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler.
nvd
CVE-2007-0219P3CRITICALCVSS 10.0v6.02007-02-13
CVE-2007-0219 [CRITICAL] CVE-2007-0219: Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlm
Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.
nvd
CVE-2008-0078P3CRITICALCVSS 9.3v5.01v6+1 more2008-02-12
CVE-2008-0078 [CRITICAL] CWE-94 CVE-2008-0078: Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6
Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."
nvd
CVE-1999-0989P4HIGHCVSS 7.5PoCv5v5.01999-12-06
CVE-1999-0989 [HIGH] CVE-1999-0989: Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to exec
Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.
nvd