cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 13 of 80
CVE-2013-3153P3CRITICALCVSS 9.3PoCv6v7+3 more2013-07-10
CVE-2013-3153 [CRITICAL] CVE-2013-3153: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3148.
nvd
CVE-2013-3161P3CRITICALCVSS 9.3PoCv9v102013-07-10
CVE-2013-3161 [CRITICAL] CVE-2013-3161: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143.
nvd
CVE-2013-3162P3CRITICALCVSS 9.3PoCv7v8+2 more2013-07-10
CVE-2013-3162 [CRITICAL] CVE-2013-3162: Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3115.
nvd
CVE-2007-2222P3CRITICALCVSS 9.3PoCv5.01v6+1 more2007-06-12
CVE-2007-2222 [CRITICAL] CWE-119 CVE-2007-2222: Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) spe Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function i
nvd
CVE-2013-3152P3CRITICALCVSS 9.3PoCv102013-07-10
CVE-2013-3152 [CRITICAL] CVE-2013-3152: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3146.
nvd
CVE-2013-3146P3CRITICALCVSS 9.3PoCv102013-07-10
CVE-2013-3146 [CRITICAL] CWE-94 CVE-2013-3146: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3152.
nvd
CVE-2007-1749P3CRITICALCVSS 9.3PoCv5.01v6+1 more2007-08-14
CVE-2007-1749 [CRITICAL] CVE-2007-1749: Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.
nvd
CVE-2007-2221P3CRITICALCVSS 9.3PoCv5.01v6+2 more2007-05-08
CVE-2007-2221 [CRITICAL] CVE-2007-2221: Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Mic Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows Vista allows remote attackers to overwrite arbitrary files via unspecified vectors, aka the "Arbitr
nvd
CVE-2014-2777P3HIGHCVSS 7.5PoCv8v9+2 more2014-06-11
CVE-2014-2777 [HIGH] CVE-2014-2777: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script wit Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-1778.
nvd
CVE-2006-1186P3CRITICALCVSS 10.0PoCv5.0.1v5.01+2 more2006-04-11
CVE-2006-1186 [CRITICAL] CVE-2006-1186: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.
nvd
CVE-2006-1185P3HIGHCVSS 7.5PoCv62006-04-11
CVE-2006-1185 [HIGH] CVE-2006-1185: Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to e Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
nvd
CVE-2007-2216P3CRITICALCVSS 9.3PoCv5.01v6+1 more2007-08-14
CVE-2007-2216 [CRITICAL] CWE-16 CVE-2007-2216: The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll proper
nvd
CVE-2006-1190P3CRITICALCVSS 10.0PoCv5.01v5.1+2 more2006-04-11
CVE-2006-1190 [CRITICAL] CVE-2006-1190: Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite informa Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
nvd
CVE-2007-3111P3CRITICALCVSS 10.0PoCv62007-06-07
CVE-2007-3111 [CRITICAL] CVE-2007-3111: Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.
nvd
CVE-2006-1388P3HIGHCVSS 7.5PoCv6.02006-03-24
CVE-2006-1388 [HIGH] CVE-2006-1388: Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.
nvd
CVE-2006-1016P3HIGHCVSS 7.5PoCv6.02006-03-07
CVE-2006-1016 [HIGH] CVE-2006-1016: Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 20 Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.
nvd
CVE-2006-1188P3HIGHCVSS 7.5PoCv5.1v5.5+6 more2006-04-11
CVE-2006-1188 [HIGH] CVE-2006-1188: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTM Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.
nvd
CVE-2007-2938P3CRITICALCVSS 10.0PoCv62007-05-31
CVE-2007-2938 [CRITICAL] CVE-2007-2938: Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoad Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and (5) SetVideoServer methods.
nvd
CVE-2006-2383P3CRITICALCVSS 9.3PoCv5.01v62006-06-13
CVE-2006-2383 [CRITICAL] CVE-2006-2383: Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remot Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.
nvd
CVE-2003-0344P3HIGHCVSS 7.5PoCv5.01v5.5+1 more2003-06-16
CVE-2003-0344 [HIGH] CVE-2003-0344: Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase