Microsoft Ie vulnerabilities
200 known vulnerabilities affecting microsoft/ie.
Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19
Vulnerabilities
Page 6 of 10
CVE-2001-1489P4MEDIUMCVSS 5.0PoCv62001-12-31
CVE-2001-1489 [MEDIUM] CVE-2001-1489: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.
nvd
CVE-2006-3472P4MEDIUMCVSS 5.0PoCv6.02006-07-10
CVE-2006-3472 [MEDIUM] CVE-2006-3472: Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via
Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with an A tag containing a long title attribute. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2006-3943P4LOWCVSS 2.6PoCv62006-07-31
CVE-2006-3943 [LOW] CVE-2006-3943: Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 all
Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties.
nvd
CVE-2006-7065P4MEDIUMCVSS 5.0PoCv6v6.0+2 more2007-03-02
CVE-2006-7065 [MEDIUM] CVE-2006-7065: Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRA
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
nvd
CVE-2005-2831P3HIGHCVSS 7.5v6.02005-12-14
CVE-2005-2831 [HIGH] CVE-2005-2831: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (a
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a
nvd
CVE-2006-3354P4MEDIUMCVSS 5.0PoCv6v6.02006-07-06
CVE-2006-3354 [MEDIUM] CVE-2006-3354: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by settin
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.
nvd
CVE-2003-0532P4HIGHCVSS 7.5v6.02003-08-27
CVE-2003-0532 [HIGH] CVE-2003-0532: Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returne
Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.
nvd
CVE-2000-0028P4LOWCVSS 2.6PoCv4.01999-12-23
CVE-2000-0028 [LOW] CVE-2000-0028: Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
nvd
CVE-2003-0823P4HIGHCVSS 7.5v6.02004-02-03
CVE-2003-0823 [HIGH] CVE-2003-0823: Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and ot
Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.
nvd
CVE-2003-0233P4HIGHCVSS 7.5v6.02003-05-12
CVE-2003-0233 [HIGH] CVE-2003-0233: Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attac
Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.
nvd
CVE-2003-0817P4HIGHCVSS 7.5v6.02004-02-03
CVE-2003-0817 [HIGH] CVE-2003-0817: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read ar
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.
nvd
CVE-2005-0056P4MEDIUMCVSS 5.1v62005-05-02
CVE-2005-0056 [MEDIUM] CVE-2005-0056: Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition For
Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
nvd
CVE-2006-0057P4HIGHCVSS 7.5v62006-01-27
CVE-2006-0057 [HIGH] CVE-2006-0057: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054
nvd
CVE-2006-4687P3MEDIUMCVSS 5.1v62006-11-14
CVE-2006-4687 [MEDIUM] CWE-119 CVE-2006-4687: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via cra
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
nvd
CVE-2007-0811P4MEDIUMCVSS 4.3PoCv6v6.02007-02-07
CVE-2007-0811 [MEDIUM] CVE-2007-0811: Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attack
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
nvd
CVE-2002-1714P4MEDIUMCVSS 5.0PoCv6.02002-12-31
CVE-2002-1714 [MEDIUM] CVE-2002-1714: Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (cr
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
nvd
CVE-2004-0867P4HIGHCVSS 7.5v6.02004-12-23
CVE-2004-0867 [HIGH] CWE-264 CVE-2004-0867: Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such a
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
nvd
CVE-2005-4827P3HIGHCVSS 7.5v6v6.02005-12-31
CVE-2005-4827 [HIGH] CVE-2005-4827: Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origi
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy ser
nvd
CVE-2003-1326P4HIGHCVSS 7.5v6.02003-02-19
CVE-2003-1326 [HIGH] CVE-2003-1326: Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security
Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."
nvd
CVE-2002-0152P4HIGHCVSS 7.5v5.12002-04-22
CVE-2002-0152 [HIGH] CVE-2002-0152: Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a d
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v.
nvd