cbcvebase.

Microsoft Ie vulnerabilities

200 known vulnerabilities affecting microsoft/ie.

Total CVEs
200
CISA KEV
0
Public exploits
75
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH65MEDIUM91LOW19

Vulnerabilities

Page 9 of 10
CVE-2003-1559P4MEDIUMCVSS 5.0v5.222003-12-31
CVE-2003-1559 [MEDIUM] CWE-200 CVE-2003-1559: Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containi Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
nvd
CVE-2004-0869P4MEDIUMCVSS 5.0v62004-09-16
CVE-2004-0869 [MEDIUM] CVE-2004-0869: Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also b Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
nvd
CVE-2002-2435P4MEDIUMCVSS 4.3v7.0.6000.16711v8.0.7600.16385+1 more2011-12-07
CVE-2002-2435 [MEDIUM] CWE-200 CVE-2002-2435: The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
nvd
CVE-2006-4888P4MEDIUMCVSS 5.0≤ 62006-09-19
CVE-2006-4888 [MEDIUM] CVE-2006-4888: Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (appl Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size than the INPUT.
nvd
CVE-2002-2125P4MEDIUMCVSS 6.4v6.02002-12-31
CVE-2002-2125 [MEDIUM] CVE-2002-2125: Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.
nvd
CVE-2005-0500P4MEDIUMCVSS 5.0v6.02005-05-02
CVE-2005-0500 [MEDIUM] CVE-2005-0500: Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.
nvd
CVE-2006-3657P4MEDIUMCVSS 5.0v62006-07-18
CVE-2006-3657 [MEDIUM] CVE-2006-3657: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow e Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow exception) via a DXImageTransform.Microsoft.Gradient ActiveX object with a long (1) StartColorStr or (2) EndColorStr property.
nvd
CVE-2005-2126P4LOWCVSS 2.6v6.02005-10-21
CVE-2005-2126 [LOW] CVE-2005-2126: The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, w The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.
nvd
CVE-2006-7030P4MEDIUMCVSS 5.0v6.02007-02-23
CVE-2006-7030 [MEDIUM] CVE-2006-7030: Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service ( Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
nvd
CVE-2006-5913P4MEDIUMCVSS 6.4v7.02006-11-15
CVE-2006-5913 [MEDIUM] CVE-2006-5913: Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a sec Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/sslnavcancel.htm with the target site in the anchor identifier, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid, or (2) trigge
nvd
CVE-2005-4679P4MEDIUMCVSS 5.0v62005-12-31
CVE-2005-4679 [MEDIUM] CVE-2005-4679: Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to spoof the URL in the st Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site.
nvd
CVE-2004-0284P4MEDIUMCVSS 5.0v6.02004-11-23
CVE-2004-0284 [MEDIUM] CVE-2004-0284: Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a de Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
nvd
CVE-2010-1991P4MEDIUMCVSS 5.0v8.0.7600.163852010-05-20
CVE-2010-1991 [MEDIUM] CWE-399 CVE-2010-1991: Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situ Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
nvd
CVE-2006-1719P4MEDIUMCVSS 5.0v62006-04-11
CVE-2006-1719 [MEDIUM] CVE-2006-1719: Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) via any Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) via any scrollbar Cascading Style Sheets (CSS) property.
nvd
CVE-2006-3658P4MEDIUMCVSS 5.0v62006-07-18
CVE-2006-3658 [MEDIUM] CVE-2006-3658: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by access Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by accessing the object references of a FolderItem ActiveX object, which triggers a null dereference in the security check.
nvd
CVE-2004-2179P4MEDIUMCVSS 5.0v3.0.12004-12-31
CVE-2004-2179 [MEDIUM] CVE-2004-2179: asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.
nvd
CVE-2004-1686P4MEDIUMCVSS 5.0v6.02004-09-15
CVE-2004-1686 [MEDIUM] CVE-2004-1686: Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.
nvd
CVE-2006-5578P4LOWCVSS 2.6≤ 62006-12-12
CVE-2006-5578 [LOW] CVE-2006-5578: Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files ( Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files (TIF) and obtain sensitive information via unspecified vectors involving certain drag and drop operations, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5577.
nvd
CVE-1999-0839P4HIGHCVSS 7.2v5v5.01999-11-29
CVE-1999-0839 [HIGH] CWE-264 CVE-1999-0839: Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by mod Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.
nvd
CVE-2007-4848P4MEDIUMCVSS 4.3v4.xv5.0+3 more2007-09-12
CVE-2007-4848 [MEDIUM] CVE-2007-4848: Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of loca Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.
nvd
Microsoft Ie vulnerabilities | cvebase