Microsoft Ie vulnerabilities
200 known vulnerabilities affecting microsoft/ie.
Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19
Vulnerabilities
Page 5 of 10
CVE-2006-6659P4MEDIUMCVSS 5.0PoCv7.02006-12-20
CVE-2006-6659 [MEDIUM] CVE-2006-6659: The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote a
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
nvd
CVE-2006-3513P4MEDIUMCVSS 5.0PoCv6.02006-07-11
CVE-2006-3513 [MEDIUM] CVE-2006-3513: danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (app
danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.
nvd
CVE-2007-0943P3MEDIUMCVSS 6.8v6.02007-08-14
CVE-2007-0943 [MEDIUM] CVE-2007-0943: Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arb
Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.
nvd
CVE-2004-2383P4MEDIUMCVSS 5.1PoCv6.02004-12-31
CVE-2004-2383 [MEDIUM] CVE-2004-2383: Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categor
nvd
CVE-2006-3873P3HIGHCVSS 7.5v6.02006-09-12
CVE-2006-3873 [HIGH] CVE-2006-3873: Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-
nvd
CVE-2006-3944P4MEDIUMCVSS 5.0PoCv62006-07-31
CVE-2006-3944 [MEDIUM] CVE-2006-3944: Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference.
nvd
CVE-2007-0356P4MEDIUMCVSS 5.0PoCv7.02007-01-19
CVE-2007-0356 [MEDIUM] CVE-2007-0356: The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) a
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.
nvd
CVE-2005-4717P4MEDIUMCVSS 5.0PoCv6.02005-12-31
CVE-2005-4717 [MEDIUM] CVE-2005-4717: Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contain
nvd
CVE-2006-3639P3HIGHCVSS 7.5v62006-08-09
CVE-2006-3639 [HIGH] CVE-2006-3639: Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when h
Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages and possibly execute code via unspecified vectors involving a crafted web page, aka "Source Element Cross-Domain Vulnerability."
nvd
CVE-2004-2434P4MEDIUMCVSS 5.0PoCv6.02004-12-31
CVE-2004-2434 [MEDIUM] CVE-2004-2434: Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser cr
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.
nvd
CVE-2000-0329P4MEDIUMCVSS 5.1PoCv4.0v4.0.1+3 more1999-11-11
CVE-2000-0329 [MEDIUM] CVE-2000-0329: A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an atta
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
nvd
CVE-2004-0479P4MEDIUMCVSS 5.0PoCv62004-07-07
CVE-2004-0479 [MEDIUM] CVE-2004-0479: Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that
Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.
nvd
CVE-2007-3550P3HIGHCVSS 7.8v6.02007-07-03
CVE-2007-3550 [HIGH] CWE-94 CVE-2007-3550: Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains
Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been dispu
nvd
CVE-2006-3910P4MEDIUMCVSS 5.0PoCv6.02006-07-28
CVE-2006-3910 [MEDIUM] CVE-2006-3910: Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a
Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) ActiveX object, which triggers a null dereference.
nvd
CVE-2000-1061P4MEDIUMCVSS 5.1PoCv4.xv5.x2000-12-11
CVE-2000-1061 [MEDIUM] CVE-2000-1061: Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create
Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the "Microsoft VM ActiveX Component" vulnerability.
nvd
CVE-2006-2385P3HIGHCVSS 7.6v6.02006-06-13
CVE-2006-2385 [HIGH] CWE-94 CVE-2006-2385: Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.
nvd
CVE-2006-3471P4MEDIUMCVSS 5.0PoCv6.02006-07-10
CVE-2006-3471 [MEDIUM] CVE-2006-3471: Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (cr
Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method.
nvd
CVE-2003-0815P3HIGHCVSS 7.5v6.02004-02-03
CVE-2003-0815 [HIGH] CVE-2003-0815: Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arb
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, a
nvd
CVE-2003-0530P3HIGHCVSS 7.5v6.02003-08-27
CVE-2003-0530 [HIGH] CVE-2003-0530: Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allo
Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.
nvd
CVE-2006-1192P4LOWCVSS 2.6PoCv5.01v62006-04-11
CVE-2006-1192 [LOW] CWE-20 CVE-2006-1192: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by sp
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability." NOTE: this is a different vulnerability than CVE-20
nvd