Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
40
actively exploited
Public exploits
360
Exploited in wild
48
Severity breakdown
CRITICAL690HIGH450MEDIUM404LOW50

Vulnerabilities

Page 12 of 80
CVE-2017-8547HIGHCVSS 7.5v10v112017-06-15
CVE-2017-8547 [HIGH] CVE-2017-8547: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from C
nvd
CVE-2017-8522HIGHCVSS 7.5v11v102017-06-15
CVE-2017-8522 [HIGH] CVE-2017-8522: Microsoft browsers in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows Microsoft browsers in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka "Scripting Engine M
nvd
CVE-2017-8529MEDIUMCVSS 6.5v11v9+1 more2017-06-15
CVE-2017-8529 [MEDIUM] CWE-119 CVE-2017-8529: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability".
nvd
CVE-2017-0228HIGHCVSS 7.5v112017-05-12
CVE-2017-0228 [HIGH] CVE-2017-0228: A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines ren A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.
nvd
CVE-2017-0226HIGHCVSS 7.5v10v112017-05-12
CVE-2017-0226 [HIGH] CVE-2017-0226: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0222.
nvd
CVE-2017-0238HIGHCVSS 7.5v9v10+1 more2017-05-12
CVE-2017-0238 [HIGH] CVE-2017-0238: A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting e A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and CVE-2017-0236.
nvd
CVE-2017-0222HIGHCVSS 8.8KEVv9v112017-05-12
CVE-2017-0222 [HIGH] CWE-787 CVE-2017-0222: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
nvd
CVE-2017-0231MEDIUMCVSS 4.3v112017-05-12
CVE-2017-0231 [MEDIUM] CWE-20 CVE-2017-0231: A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Br A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability."
nvd
CVE-2017-0064MEDIUMCVSS 6.5v9v10+1 more2017-05-12
CVE-2017-0064 [MEDIUM] CVE-2017-0064: A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed Content warnings, aka "Internet Explorer Security Feature Bypass Vulnerability."
nvd
CVE-2017-0201HIGHCVSS 7.5v9v102017-04-12
CVE-2017-0201 [HIGH] CVE-2017-0201: A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VB A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VBScript engines render when handling objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is un
nvd
CVE-2017-0202HIGHCVSS 7.5PoCv112017-04-12
CVE-2017-0202 [HIGH] CWE-119 CVE-2017-0202: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, a.k.a. "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2017-0210HIGHCVSS 8.8KEVv10v112017-04-12
CVE-2017-0210 [HIGH] CVE-2017-0210: An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cros An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2017-0149HIGHCVSS 8.8KEVv9v10+1 more2017-03-17
CVE-2017-0149 [HIGH] CVE-2017-0149: Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
nvd
CVE-2017-0130HIGHCVSS 7.5v9v10+1 more2017-03-17
CVE-2017-0130 [HIGH] CVE-2017-0130: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerability is different from that described in CVE-2017-0040.
nvd
CVE-2017-0040HIGHCVSS 7.5v9v10+1 more2017-03-17
CVE-2017-0040 [HIGH] CWE-119 CVE-2017-0040: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerability is different from that described in CVE-2017-0130.
nvd
CVE-2017-0018HIGHCVSS 7.5v10v112017-03-17
CVE-2017-0018 [HIGH] CWE-119 CVE-2017-0018: Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a de Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0037 and CVE-2017-0149.
nvd
CVE-2017-0009MEDIUMCVSS 4.3v9v10+1 more2017-03-17
CVE-2017-0009 [MEDIUM] CWE-200 CVE-2017-0009: Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0011, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.
nvd
CVE-2017-0049MEDIUMCVSS 4.3v112017-03-17
CVE-2017-0049 [MEDIUM] CVE-2017-0049: The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive in The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0018, and CVE-2017-0037.
nvd
CVE-2017-0033MEDIUMCVSS 4.3v112017-03-17
CVE-2017-0033 [MEDIUM] CVE-2017-0033: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0069.
nvd
CVE-2017-0008MEDIUMCVSS 4.3v9v10+1 more2017-03-17
CVE-2017-0008 [MEDIUM] CWE-200 CVE-2017-0008: Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009 and CVE-2017-0059.
nvd