Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
40
actively exploited
Public exploits
364
Exploited in wild
48
Severity breakdown
CRITICAL690HIGH450MEDIUM404LOW50
Vulnerabilities
Page 15 of 80
CVE-2016-3293HIGHCVSS 7.5v9v10+1 more2016-08-09
CVE-2016-3293 [HIGH] CWE-119 CVE-2016-3293: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to execute arbitrary code v
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2016-3288HIGHCVSS 7.5PoCv112016-08-09
CVE-2016-3288 [HIGH] CWE-119 CVE-2016-3288: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web p
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290.
nvd
CVE-2016-3290HIGHCVSS 7.5v112016-08-09
CVE-2016-3290 [HIGH] CVE-2016-3290: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web p
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3288.
nvd
CVE-2016-3322HIGHCVSS 7.5v112016-08-09
CVE-2016-3322 [HIGH] CVE-2016-3322: Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a craft
Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3289.
nvd
CVE-2016-3326MEDIUMCVSS 5.3v9v10+1 more2016-08-09
CVE-2016-3326 [MEDIUM] CWE-200 CVE-2016-3326: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive informa
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3327.
nvd
CVE-2016-3327MEDIUMCVSS 5.3v9v10+1 more2016-08-09
CVE-2016-3327 [MEDIUM] CVE-2016-3327: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive informa
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3326.
nvd
CVE-2016-3329MEDIUMCVSS 5.3v9v10+1 more2016-08-09
CVE-2016-3329 [MEDIUM] CWE-200 CVE-2016-3329: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence of files via a crafted webpage, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2016-3321LOWCVSS 2.5PoCv10v112016-08-09
CVE-2016-3321 [LOW] CWE-200 CVE-2016-3321: Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depend
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2016-3248HIGHCVSS 8.8v9v10+1 more2016-07-13
CVE-2016-3248 [HIGH] CWE-119 CVE-2016-3248: The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft I
The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a differen
nvd
CVE-2016-3242HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3242 [HIGH] CVE-2016-3242: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3240 and CVE-2016-3241.
nvd
CVE-2016-3240HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3240 [HIGH] CWE-119 CVE-2016-3240: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3241 and CVE-2016-3242.
nvd
CVE-2016-3241HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3241 [HIGH] CVE-2016-3241: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3240 and CVE-2016-3242.
nvd
CVE-2016-3259HIGHCVSS 8.8v9v10+1 more2016-07-13
CVE-2016-3259 [HIGH] CVE-2016-3259: The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft I
The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulner
nvd
CVE-2016-3243HIGHCVSS 7.5v10v112016-07-13
CVE-2016-3243 [HIGH] CWE-119 CVE-2016-3243: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-3260HIGHCVSS 8.8v112016-07-13
CVE-2016-3260 [HIGH] CWE-119 CVE-2016-3260: The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft I
The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2016-3264HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3264 [HIGH] CWE-119 CVE-2016-3264: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2016-3204HIGHCVSS 8.8v9v10+1 more2016-07-13
CVE-2016-3204 [HIGH] CWE-119 CVE-2016-3204: The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explor
The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2016-3261MEDIUMCVSS 5.3v112016-07-13
CVE-2016-3261 [MEDIUM] CWE-200 CVE-2016-3261: Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information via a crafted
Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2016-3277MEDIUMCVSS 5.3v10v112016-07-13
CVE-2016-3277 [MEDIUM] CWE-200 CVE-2016-3277: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2016-3273MEDIUMCVSS 5.3v9v10+1 more2016-07-13
CVE-2016-3273 [MEDIUM] CWE-200 CVE-2016-3273: The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly rest
The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd