cbcvebase.

Microsoft Ie vulnerabilities

200 known vulnerabilities affecting microsoft/ie.

Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19

Vulnerabilities

Page 8 of 10
CVE-2004-0866P4HIGHCVSS 7.5v6.02004-09-16
CVE-2004-0866 [HIGH] CVE-2004-0866: Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such a Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-2010-5071P4MEDIUMCVSS 5.0v7.0.6000.16711v8.0.7600.16385+1 more2011-12-07
CVE-2010-5071 [MEDIUM] CWE-264 CVE-2010-5071: The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restr The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
nvd
CVE-2005-4269P4HIGHCVSS 7.8v6.02005-12-15
CVE-2005-4269 [HIGH] CVE-2005-4269: mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to c mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form.
nvd
CVE-2007-1091P4MEDIUMCVSS 6.8v6.0v7.02007-02-26
CVE-2007-1091 [MEDIUM] CVE-2007-1091: Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof th Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
nvd
CVE-2011-2383P4MEDIUMCVSS 4.3v92011-06-03
CVE-2011-2383 [MEDIUM] CWE-20 CVE-2011-2383: Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop action Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL that redirects to a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue
nvd
CVE-2000-0160P4HIGHCVSS 7.6v4.x2000-02-21
CVE-2000-0160 [HIGH] CVE-2000-0160: The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attack The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
nvd
CVE-2004-1331P4LOWCVSS 2.6v6.02004-11-16
CVE-2004-1331 [LOW] CVE-2004-1331: The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
nvd
CVE-2006-5577P4MEDIUMCVSS 4.3≤ 62006-12-12
CVE-2006-5577 [MEDIUM] CVE-2006-5577: Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information vi Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5578.
nvd
CVE-2011-2382P4MEDIUMCVSS 4.3v92011-06-03
CVE-2011-2382 [MEDIUM] CWE-20 CVE-2011-2382: Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.
nvd
CVE-2009-2057P4MEDIUMCVSS 5.8v5.0v5.22+1 more2009-06-15
CVE-2009-2057 [MEDIUM] CWE-287 CVE-2009-2057: Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a documen Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
nvd
CVE-2003-0114P4MEDIUMCVSS 5.0v6.02003-05-12
CVE-2003-0114 [MEDIUM] CVE-2003-0114: The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.
nvd
CVE-2002-1186P4MEDIUMCVSS 5.0v6.02002-12-11
CVE-2002-1186 [MEDIUM] CVE-2002-1186: Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded char Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."
nvd
CVE-1999-0876P4CRITICALCVSS 10.0v3.0v3.1+1 more2000-01-04
CVE-1999-0876 [CRITICAL] CWE-119 CVE-1999-0876: Buffer overflow in Internet Explorer 4.0 via EMBED tag. Buffer overflow in Internet Explorer 4.0 via EMBED tag.
nvd
CVE-2005-3240P4MEDIUMCVSS 5.1v6.02005-12-31
CVE-2005-3240 [MEDIUM] CWE-362 CVE-2005-3240: Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.
nvd
CVE-2004-0475P4MEDIUMCVSS 5.1v6.02004-07-07
CVE-2004-0475 [MEDIUM] CVE-2004-0475: The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute ar The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm. NOTE: this bug may overlap CVE-2003-1041.
nvd
CVE-2009-2069P4MEDIUMCVSS 5.8v5.0v5.22+1 more2009-06-15
CVE-2009-2069 [MEDIUM] CWE-287 CVE-2009-2069: Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response pag
nvd
CVE-2006-2900P4MEDIUMCVSS 4.0v5.01v62006-06-07
CVE-2006-2900 [MEDIUM] CWE-200 CVE-2006-2900: Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then
nvd
CVE-2009-2576P4MEDIUMCVSS 5.0v2.0v2.0_beta+23 more2009-07-22
CVE-2009-2576 [MEDIUM] CVE-2009-2576: Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of s Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
nvd
CVE-2003-0116P4MEDIUMCVSS 5.0v6.02003-05-12
CVE-2003-0116 [MEDIUM] CVE-2003-0116: Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet inpu Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."
nvd
CVE-2004-0719P4HIGHCVSS 7.5v6.02004-07-27
CVE-2004-0719 [HIGH] CVE-2004-0719: Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, doe Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
nvd
Microsoft Ie vulnerabilities | cvebase