cbcvebase.

Microsoft Ie vulnerabilities

200 known vulnerabilities affecting microsoft/ie.

Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19

Vulnerabilities

Page 4 of 10
CVE-2006-1303P3CRITICALCVSS 9.3v5.0.1v6.02006-06-13
CVE-2006-1303 [CRITICAL] CWE-94 CVE-2006-1303: Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier a Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImag
nvd
CVE-2006-2094P4MEDIUMCVSS 5.1PoCv5v5.0+2 more2006-04-29
CVE-2006-2094 [MEDIUM] CWE-362 CVE-2006-2094: Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into
nvd
CVE-2006-2378P3MEDIUMCVSS 6.8v6.02006-06-13
CVE-2006-2378 [MEDIUM] CVE-2006-2378: Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and S Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
nvd
CVE-2009-2433P4MEDIUMCVSS 4.3PoCv8.0b2009-07-10
CVE-2009-2433 [MEDIUM] CWE-119 CVE-2009-2433: Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote a Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
nvd
CVE-2006-4697P3CRITICALCVSS 9.3v6.02007-02-13
CVE-2006-4697 [CRITICAL] CVE-2006-4697: Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX co Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.
nvd
CVE-2007-1499P4MEDIUMCVSS 4.3PoCv7.02007-03-17
CVE-2007-1499 [MEDIUM] CWE-79 CVE-2007-1499: Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navi
nvd
CVE-2006-4301P4MEDIUMCVSS 5.0PoCv6.02006-08-23
CVE-2006-4301 [MEDIUM] CWE-20 CVE-2006-4301: Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1) DXImageTransform.Microsoft.MaskFilter.1, (2) DXImageTransform.Microsoft.Chroma.1, and (3) DX3DTransfor
nvd
CVE-2006-3869P3HIGHCVSS 7.5v6.02006-08-23
CVE-2006-3869 [HIGH] CVE-2006-3869: Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
nvd
CVE-2005-0055P3HIGHCVSS 7.5v6.02005-05-02
CVE-2005-0055 [HIGH] CVE-2005-0055: Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML me Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."
nvd
CVE-2004-2090P4MEDIUMCVSS 5.0PoCv6.02004-02-07
CVE-2004-2090 [MEDIUM] CVE-2004-2090: Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
nvd
CVE-2003-1027P3CRITICALCVSS 10.0v6.02004-01-20
CVE-2003-1027 [CRITICAL] CVE-2003-1027: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and o Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and
nvd
CVE-2006-3451P3HIGHCVSS 7.5v5.0v62006-08-08
CVE-2006-3451 [HIGH] CWE-20 CVE-2006-3451: Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are u Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2006-3450P3HIGHCVSS 7.5v6.02006-08-08
CVE-2006-3450 [HIGH] CWE-20 CVE-2006-3450: Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the documen Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file.
nvd
CVE-2006-4560P3HIGHCVSS 7.5v62006-09-06
CVE-2006-4560 [HIGH] CVE-2006-4560: Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pin
nvd
CVE-2006-2766P4LOWCVSS 2.6PoCv6.02006-06-02
CVE-2006-2766 [LOW] CVE-2006-2766: Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
nvd
CVE-2004-0526P4MEDIUMCVSS 5.0PoCv6.02004-08-06
CVE-2004-0526 [MEDIUM] CVE-2004-0526: Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL i Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
nvd
CVE-2004-0985P3CRITICALCVSS 10.0v6.02004-12-31
CVE-2004-0985 [CRITICAL] CVE-2004-0985: Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demons Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write to a .hta file that is interpreted in the Local Zone by HTML Help.
nvd
CVE-2007-5344P3MEDIUMCVSS 6.8v5.xv6.02007-12-12
CVE-2007-5344 [MEDIUM] CVE-2007-5344: Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a c Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption, related to uninitialized or deleted objects, a different issue than CVE-2007-3902 and CVE-2007-3903, and a va
nvd
CVE-2006-3638P3HIGHCVSS 7.5v6.02006-08-08
CVE-2006-3638 [HIGH] CWE-119 CVE-2006-3638: Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which all Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."
nvd
CVE-2007-3903P3MEDIUMCVSS 6.8v6.02007-12-12
CVE-2007-3903 [MEDIUM] CVE-2007-3903: Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitiali Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-2007-5344, a variant of "Uninitialized Memory Corruption Vulnerability."
nvd
Microsoft Ie vulnerabilities | cvebase