Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 15 of 80
CVE-2014-1778P3MEDIUMCVSS 6.8PoCv8v9+2 more2014-06-11
CVE-2014-1778 [MEDIUM] CWE-264 CVE-2014-1778: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script wit
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.
nvd
CVE-2002-1254P3HIGHCVSS 7.5PoCv5.5v6.02002-12-11
CVE-2002-1254 [HIGH] CVE-2002-1254: Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
nvd
CVE-2002-1217P3HIGHCVSS 7.5PoCv5.5v6.02002-10-28
CVE-2002-1217 [HIGH] CVE-2002-1217: Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses and domain restrictions.
nvd
CVE-2002-0371P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2002-07-03
CVE-2002-0371 [HIGH] CVE-2002-0371: Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0,
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
nvd
CVE-2005-1988P3MEDIUMCVSS 5.1PoCv5.01v5.52005-08-10
CVE-2005-1988 [MEDIUM] CVE-2005-1988: Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbi
Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".
nvd
CVE-2005-0553P3MEDIUMCVSS 5.1PoCv5.01v5.5+1 more2005-05-02
CVE-2005-0553 [MEDIUM] CVE-2005-0553: Race condition in the memory management routines in the DHTML object processor in Microsoft Internet
Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
nvd
CVE-2013-5045P3MEDIUMCVSS 6.2PoCv10v112013-12-11
CVE-2013-5045 [MEDIUM] CWE-20 CVE-2013-5045: Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mec
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2003-1026P3CRITICALCVSS 9.3PoCv5.0v5.0.1+2 more2004-01-20
CVE-2003-1026 [CRITICAL] CWE-264 CVE-2003-1026: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javas
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
nvd
CVE-2007-0612P3HIGHCVSS 7.8PoCv5.0.1v5.5+2 more2007-01-31
CVE-2007-0612 [HIGH] CVE-2007-0612: Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to
Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfi
nvd
CVE-2016-3325P3LOWCVSS 3.1PoCv112016-09-14
CVE-2016-3325 [LOW] CWE-200 CVE-2016-3325: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive informa
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-1999-0702P3CRITICALCVSS 10.0PoCv4.0.1v5.01999-09-10
CVE-1999-0702 [CRITICAL] CWE-94 CVE-1999-0702: Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Exp
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.
nvd
CVE-2008-3012P2CRITICALCVSS 9.3v62008-09-11
CVE-2008-3012 [CRITICAL] CWE-119 CVE-2008-3012: gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 an
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 20
nvd
CVE-2009-1140P3HIGHCVSS 7.1PoCv6v7+1 more2009-06-10
CVE-2009-1140 [HIGH] CWE-200 CVE-2009-1140: Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server
Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerab
nvd
CVE-2016-3259P3HIGHCVSS 8.8v9v10+1 more2016-07-13
CVE-2016-3259 [HIGH] CVE-2016-3259: The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft I
The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulner
nvd
CVE-2009-1531P3CRITICALCVSS 9.3v72009-06-10
CVE-2009-1531 [CRITICAL] CWE-399 CVE-2009-1531: Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, S
Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code via frequent calls to the getElementsByTagName function combined with the creation of an object during reordering of elements, followed by an onreadystatechange e
nvd
CVE-2003-0113P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2003-05-12
CVE-2003-0113 [HIGH] CVE-2003-0113: Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attacke
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.
nvd
CVE-2019-0768P3MEDIUMCVSS 4.3PoCv112019-04-09
CVE-2019-0768 [MEDIUM] CVE-2019-0768: A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761.
nvd
CVE-2011-2001P3CRITICALCVSS 9.3v6v7+2 more2011-10-12
CVE-2011-2001 [CRITICAL] CVE-2011-2001: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual Function Table Corruption Remote Code Execution Vulnerability."
nvd
CVE-2009-0554P3HIGHCVSS 8.8v6v7+1 more2009-04-15
CVE-2009-0554 [HIGH] CWE-399 CVE-2009-0554: Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows S
Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka
nvd
CVE-2006-3281P3MEDIUMCVSS 5.1PoCv6.02006-06-28
CVE-2006-3281 [MEDIUM] CWE-20 CVE-2006-3281: Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote u
Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose extension contains the CLSID Key identifier for HTML Applications (HTA), aka "Folder GUID Code Exec
nvd