cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 1 of 80
CVE-2015-0311P1CRITICALCVSS 9.8KEVPoCRansomwarev10v112015-01-23
CVE-2015-0311 [CRITICAL] CVE-2015-0311: Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
nvd
CVE-2015-0313P1CRITICALCVSS 9.8KEVPoCv10v112015-02-02
CVE-2015-0313 [CRITICAL] CWE-416 CVE-2015-0313: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-20
nvd
CVE-2010-0249P1HIGHCVSS 8.8KEVPoCv5.0.1v6+2 more2010-01-15
CVE-2010-0249 [HIGH] CWE-416 CVE-2010-0249: Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to in
nvd
CVE-2016-0189P1HIGHCVSS 7.5KEVPoCRansomwarev9v10+1 more2016-05-11
CVE-2016-0189 [HIGH] CVE-2016-0189: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 t The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
nvd
CVE-2013-3893P1HIGHCVSS 8.8KEVPoCv6v7+4 more2013-09-18
CVE-2013-3893 [HIGH] CWE-399 CVE-2013-3893: Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Intern Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.
nvd
CVE-2014-0322P1HIGHCVSS 8.8KEVPoCv9v102014-02-14
CVE-2014-0322 [HIGH] CWE-416 CVE-2014-0322: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to exec Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
nvd
CVE-2010-3962P1HIGHCVSS 8.1KEVPoCv6v7+1 more2010-11-05
CVE-2010-3962 [HIGH] CWE-416 CVE-2010-3962: Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to e Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
nvd
CVE-2013-2551P1HIGHCVSS 8.8KEVPoCRansomwarev6v7+3 more2013-03-11
CVE-2013-2551 [HIGH] CVE-2013-2551: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and
nvd
CVE-2012-4792P1HIGHCVSS 8.8KEVPoCv6v7+1 more2012-12-30
CVE-2012-4792 [HIGH] CWE-416 CVE-2012-4792: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to e Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
nvd
CVE-2019-0752P1HIGHCVSS 7.5KEVPoCRansomwarev11v102019-04-09
CVE-2019-0752 [HIGH] CVE-2019-0752: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.
nvd
CVE-2013-3897P1HIGHCVSS 8.8KEVPoCv6v7+4 more2013-10-09
CVE-2013-3897 [HIGH] CWE-416 CVE-2013-3897: Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explor Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Inter
nvd
CVE-2012-4969P1HIGHCVSS 8.1KEVPoCv6v7+2 more2012-09-18
CVE-2012-4969 [HIGH] CWE-416 CVE-2012-4969: Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Exp Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
nvd
CVE-2017-0037P1HIGHCVSS 8.1KEVPoCv112017-02-26
CVE-2017-0037 [HIGH] CWE-843 CVE-2017-0037: Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout:: Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that op
nvd
CVE-2013-1347P1HIGHCVSS 8.8KEVPoCv82013-05-05
CVE-2013-1347 [HIGH] CWE-416 CVE-2013-1347: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
nvd
CVE-2020-0674P1HIGHCVSS 7.5KEVPoCv9v10+1 more2020-02-11
CVE-2020-0674 [HIGH] CVE-2020-0674: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
nvd
CVE-2010-0806P1HIGHCVSS 8.8KEVPoCv5.01v6+2 more2010-03-10
CVE-2010-0806 [HIGH] CWE-399 CVE-2010-0806: Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet E Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2013-3163P1HIGHCVSS 8.8KEVPoCv8v9+1 more2013-07-10
CVE-2013-3163 [HIGH] CVE-2013-3163: Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.
nvd
CVE-2015-2419P1HIGHCVSS 8.8KEVPoCRansomwarev10v112015-07-14
CVE-2015-2419 [HIGH] CWE-787 CVE-2015-2419: JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
nvd
CVE-2019-1429P1HIGHCVSS 7.5KEVPoCv9v10+1 more2019-11-12
CVE-2019-1429 [HIGH] CVE-2019-1429: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
nvd
CVE-2019-0541P1HIGHCVSS 8.8KEVPoCv11v9+1 more2019-01-08
CVE-2019-0541 [HIGH] CWE-77 CVE-2019-0541: A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
nvd
1 / 80Next →
Microsoft Internet Explorer vulnerabilities | cvebase