Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 14 of 80
CVE-2009-0341P3CRITICALCVSS 9.3PoCv72009-01-29
CVE-2009-0341 [CRITICAL] CWE-119 CVE-2009-0341: The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers
The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.
nvd
CVE-2007-3493P3HIGHCVSS 7.5PoCv7.02007-06-29
CVE-2007-3493 [HIGH] CVE-2007-3493: A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.
nvd
CVE-2005-0555P3HIGHCVSS 7.5PoCv5.01v5.5+1 more2005-04-12
CVE-2005-0555 [HIGH] CVE-2005-0555: Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote
Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."
nvd
CVE-2016-3388P3MEDIUMCVSS 5.3PoCv10v112016-10-14
CVE-2016-3388 [MEDIUM] CVE-2016-3388: Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387.
nvd
CVE-2004-1166P3HIGHCVSS 7.5PoCv6.02004-12-31
CVE-2004-1166 [HIGH] CWE-94 CVE-2004-1166: CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
nvd
CVE-2004-0214P3CRITICALCVSS 10.0PoCv6.0.29002004-11-03
CVE-2004-0214 [CRITICAL] CVE-2004-0214: Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
nvd
CVE-2010-1175P3CRITICALCVSS 9.3PoCv7.02010-03-29
CVE-2010-1175 [CRITICAL] CVE-2010-1175: Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to hav
Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."
nvd
CVE-2005-0554P3HIGHCVSS 7.5PoCv5.01v5.5+1 more2005-05-02
CVE-2005-0554 [HIGH] CVE-2005-0554: Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote a
Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
nvd
CVE-2008-2281P3CRITICALCVSS 9.3PoCv6.0v7.02008-05-18
CVE-2008-2281 [CRITICAL] CVE-2008-2281: Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.
nvd
CVE-2017-11906P3MEDIUMCVSS 5.3PoCv11v9+1 more2017-12-12
CVE-2017-11906 [MEDIUM] CVE-2017-11906: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handles objects in memory, aka "Scripting
nvd
CVE-2006-4193P3HIGHCVSS 7.5PoCv6.02006-08-17
CVE-2006-4193 [HIGH] CVE-2006-4193: Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a d
Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certa
nvd
CVE-2012-0155P3CRITICALCVSS 9.3v92012-02-14
CVE-2012-0155 [CRITICAL] CWE-94 CVE-2012-0155: Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attack
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Remote Code Execution Vulnerability."
nvd
CVE-2004-0842P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2004-12-23
CVE-2004-0842 [HIGH] CVE-2004-0842: Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "@;/*" string, possibly due to a missing comment terminator that may c
nvd
CVE-2003-0309P3HIGHCVSS 7.5PoCv6.0.28002003-06-09
CVE-2003-0309 [HIGH] CVE-2003-0309: Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions an
Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a
nvd
CVE-2008-5750P3MEDIUMCVSS 6.8PoCv82008-12-29
CVE-2008-5750 [MEDIUM] CWE-94 CVE-2008-5750: Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows re
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
nvd
CVE-2008-3014P2CRITICALCVSS 9.3v62008-09-11
CVE-2008-3014 [CRITICAL] CWE-119 CVE-2008-3014: Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3,
Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services
nvd
CVE-2005-1989P3HIGHCVSS 7.5PoCv5.01v5.52005-08-10
CVE-2005-1989 [HIGH] CVE-2005-1989: Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain infor
Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".
nvd
CVE-2006-3280P3HIGHCVSS 7.5PoCv6.02006-06-28
CVE-2006-3280 [HIGH] CVE-2006-3280: Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access rest
Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the oute
nvd
CVE-2003-1328P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2003-02-19
CVE-2003-1328 [HIGH] CVE-2003-1328: The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of
The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."
nvd
CVE-2003-0809P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2003-11-17
CVE-2003-0809 [HIGH] CVE-2003-0809: Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server d
Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.
nvd