cbcvebase.

Microsoft Ie vulnerabilities

200 known vulnerabilities affecting microsoft/ie.

Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19

Vulnerabilities

Page 7 of 10
CVE-2005-2830P4MEDIUMCVSS 5.0v6.02005-12-14
CVE-2005-2830 [MEDIUM] CVE-2005-2830: Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic A Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."
nvd
CVE-2003-0814P4HIGHCVSS 7.5v6.02004-02-03
CVE-2003-0814 [HIGH] CVE-2003-0814: Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.
nvd
CVE-2006-3510P4LOWCVSS 2.6PoCv6.02006-07-11
CVE-2006-3510 [LOW] CVE-2006-3510: The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 al The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
nvd
CVE-2012-1545P4MEDIUMCVSS 5.8v102012-03-09
CVE-2012-1545 [MEDIUM] CWE-119 CVE-2012-1545: Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
nvd
CVE-2003-0531P4HIGHCVSS 7.5v6.02003-08-27
CVE-2003-0531 [HIGH] CVE-2003-0531: Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in t Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.
nvd
CVE-2001-0665P4HIGHCVSS 7.5≤ 62001-10-30
CVE-2001-0665 [HIGH] CVE-2001-0665: Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automat Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability."
nvd
CVE-2005-0054P4MEDIUMCVSS 5.1v62005-05-02
CVE-2005-0054 [MEDIUM] CVE-2005-0054: Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."
nvd
CVE-2003-0513P4HIGHCVSS 7.5v6.02004-04-15
CVE-2003-0513 [HIGH] CVE-2003-0513: Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
nvd
CVE-2006-5884P4HIGHCVSS 7.5v62006-11-14
CVE-2006-5884 [HIGH] CVE-2006-5884: Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Expl Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.
nvd
CVE-2004-1155P4HIGHCVSS 7.5v5.0.1v5.2.3+2 more2004-12-31
CVE-2004-1155 [HIGH] CVE-2004-1155: Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting c Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows
nvd
CVE-2003-0115P4HIGHCVSS 7.5v6.02003-05-12
CVE-2003-0115 [HIGH] CVE-2003-0115: Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed dur Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.
nvd
CVE-2006-5544P4MEDIUMCVSS 6.4v7.02006-10-26
CVE-2006-5544 [MEDIUM] CVE-2006-5544: Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof th Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which causes the address bar to omit some characters from the URL.
nvd
CVE-2004-0843P4MEDIUMCVSS 5.0v62004-11-03
CVE-2004-0843 [MEDIUM] CVE-2004-0843: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attacke Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
nvd
CVE-2005-4089P4HIGHCVSS 7.1v6.02005-12-08
CVE-2005-4089 [HIGH] CWE-264 CVE-2005-4089: Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulner
nvd
CVE-2003-1028P4MEDIUMCVSS 5.0v6.02004-01-20
CVE-2003-1028 [MEDIUM] CVE-2003-1028: The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directo The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
nvd
CVE-2002-1185P4MEDIUMCVSS 5.0v6.02002-12-11
CVE-2002-1185 [MEDIUM] CVE-2002-1185: Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when ope Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
nvd
CVE-2004-0844P4MEDIUMCVSS 5.0v62004-11-03
CVE-2004-0844 [MEDIUM] CVE-2004-0844: Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter dis Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."
nvd
CVE-2006-3640P4MEDIUMCVSS 5.0v62006-08-09
CVE-2006-3640 [MEDIUM] CVE-2006-3640: Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between p Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited web pages in other domains or zones, aka "Window Location Information Disclosure Vulnerability."
nvd
CVE-2005-2829P4MEDIUMCVSS 5.1v6.02005-12-14
CVE-2005-2829 [MEDIUM] CVE-2005-2829: Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Downloa
nvd
CVE-2004-0845P4MEDIUMCVSS 6.4v62004-11-03
CVE-2004-0845 [MEDIUM] CVE-2004-0845: Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attacker Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
nvd