cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 16 of 80
CVE-2011-1961P3CRITICALCVSS 9.3v6v7+2 more2011-08-10
CVE-2011-1961 [CRITICAL] CVE-2011-1961: The telnet URI handler in Microsoft Internet Explorer 6 through 9 does not properly launch the handl The telnet URI handler in Microsoft Internet Explorer 6 through 9 does not properly launch the handler application, which allows remote attackers to execute arbitrary programs via a crafted web site, aka "Telnet Handler Remote Code Execution Vulnerability."
nvd
CVE-2005-0553P3MEDIUMCVSS 5.1PoCv5.01v5.5+1 more2005-05-02
CVE-2005-0553 [MEDIUM] CVE-2005-0553: Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".
nvd
CVE-2009-1918P3CRITICALCVSS 10.0v6v7+2 more2009-07-29
CVE-2009-1918 [CRITICAL] CWE-94 CVE-2009-1918: Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and S Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle table operations, which allows remote attackers to execute arbitrary code via a cra
nvd
CVE-2014-0271P3CRITICALCVSS 9.3v6v7+4 more2014-02-12
CVE-2014-0271 [CRITICAL] CWE-119 CVE-2014-0271: The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allow The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."
nvd
CVE-2003-0816P4HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2004-02-03
CVE-2003-0816 [HIGH] CVE-2003-0816: Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag fo
nvd
CVE-2016-3211P3HIGHCVSS 8.8v9v10+1 more2016-06-16
CVE-2016-3211 [HIGH] CVE-2016-3211: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0199 and CVE-2016-0200.
nvd
CVE-2014-1771P3MEDIUMCVSS 6.8PoCv6v7+4 more2014-06-11
CVE-2014-1771 [MEDIUM] CWE-310 CVE-2014-1771: SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certifica SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerabil
nvd
CVE-2018-1004P3HIGHCVSS 8.8v92018-04-12
CVE-2018-1004 [HIGH] CWE-787 CVE-2018-1004: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.
nvd
CVE-2008-3477P3CRITICALCVSS 9.3v5.01v6+1 more2008-10-15
CVE-2008-3477 [CRITICAL] CWE-399 CVE-2008-3477: Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index e
nvd
CVE-2009-1528P3CRITICALCVSS 9.3v6v72009-06-10
CVE-2009-1528 [CRITICAL] CWE-399 CVE-2009-1528: Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for V Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitrary code via a large number of concurrent, asynchronous XMLHttpRequest calls, aka "HTML Object Memory
nvd
CVE-2009-2503P3CRITICALCVSS 9.3v62009-10-14
CVE-2009-2503 [CRITICAL] CWE-94 CVE-2009-2503: GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office X GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold
nvd
CVE-2003-0838P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2003-11-17
CVE-2003-0838 [HIGH] CVE-2003-0838: Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrar Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532,
nvd
CVE-2014-4109P3CRITICALCVSS 9.3v6v7+4 more2014-09-10
CVE-2014-4109 [CRITICAL] CVE-2014-4109: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE
nvd
CVE-2005-1990P4MEDIUMCVSS 5.1PoCv5.01v5.52005-08-10
CVE-2005-1990 [MEDIUM] CVE-2005-1990: Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (applicatio Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll,
nvd
CVE-2010-3328P3HIGHCVSS 8.8v6v7+1 more2010-10-13
CVE-2010-3328 [HIGH] CWE-416 CVE-2010-3328: Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Inte Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2003-0701P3HIGHCVSS 7.5PoCv5.01v5.5+1 more2003-08-27
CVE-2003-0701 [HIGH] CVE-2003-0701: Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.
nvd
CVE-2014-1763P3CRITICALCVSS 10.0v9v10+1 more2014-04-27
CVE-2014-1763 [CRITICAL] CWE-399 CVE-2014-1763: Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2009-1532P3HIGHCVSS 8.8v82009-06-10
CVE-2009-1532 [HIGH] CWE-787 CVE-2009-1532: Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, S Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, SP1, and SP2; and 8 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via "malformed row property references" that trigger an access of an object that (1) was not properly initialized or
nvd
CVE-2004-2291P3HIGHCVSS 7.5PoCv5.5v6.02004-12-31
CVE-2004-2291 [HIGH] CVE-2004-2291: Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code vi Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.
nvd
CVE-2006-7206P3HIGHCVSS 7.8PoCv62007-06-22
CVE-2006-7206 [HIGH] CVE-2006-7206: Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase