cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 16 of 80
CVE-2009-2500P2CRITICALCVSS 9.3v62009-10-14
CVE-2009-2500 [CRITICAL] CWE-189 CVE-2009-2500: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3 Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP
nvd
CVE-2011-1961P3CRITICALCVSS 9.3v6v7+2 more2011-08-10
CVE-2011-1961 [CRITICAL] CVE-2011-1961: The telnet URI handler in Microsoft Internet Explorer 6 through 9 does not properly launch the handl The telnet URI handler in Microsoft Internet Explorer 6 through 9 does not properly launch the handler application, which allows remote attackers to execute arbitrary programs via a crafted web site, aka "Telnet Handler Remote Code Execution Vulnerability."
nvd
CVE-2014-0271P3CRITICALCVSS 9.3v6v7+4 more2014-02-12
CVE-2014-0271 [CRITICAL] CWE-119 CVE-2014-0271: The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allow The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."
nvd
CVE-2003-0816P4HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2004-02-03
CVE-2003-0816 [HIGH] CVE-2003-0816: Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag fo
nvd
CVE-2016-3211P3HIGHCVSS 8.8v9v10+1 more2016-06-16
CVE-2016-3211 [HIGH] CVE-2016-3211: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0199 and CVE-2016-0200.
nvd
CVE-2014-1771P3MEDIUMCVSS 6.8PoCv6v7+4 more2014-06-11
CVE-2014-1771 [MEDIUM] CWE-310 CVE-2014-1771: SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certifica SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerabil
nvd
CVE-2003-0838P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2003-11-17
CVE-2003-0838 [HIGH] CVE-2003-0838: Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrar Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532,
nvd
CVE-2008-3477P3CRITICALCVSS 9.3v5.01v6+1 more2008-10-15
CVE-2008-3477 [CRITICAL] CWE-399 CVE-2008-3477: Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index e
nvd
CVE-2009-1528P3CRITICALCVSS 9.3v6v72009-06-10
CVE-2009-1528 [CRITICAL] CWE-399 CVE-2009-1528: Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for V Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitrary code via a large number of concurrent, asynchronous XMLHttpRequest calls, aka "HTML Object Memory
nvd
CVE-2009-2503P3CRITICALCVSS 9.3v62009-10-14
CVE-2009-2503 [CRITICAL] CWE-94 CVE-2009-2503: GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office X GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold
nvd
CVE-2009-1918P3CRITICALCVSS 10.0v6v7+2 more2009-07-29
CVE-2009-1918 [CRITICAL] CWE-94 CVE-2009-1918: Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and S Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle table operations, which allows remote attackers to execute arbitrary code via a cra
nvd
CVE-2011-1346P3CRITICALCVSS 9.3v82011-03-10
CVE-2011-1346 [CRITICAL] CVE-2011-1346: Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to e Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
nvd
CVE-2014-4109P3CRITICALCVSS 9.3v6v7+4 more2014-09-10
CVE-2014-4109 [CRITICAL] CVE-2014-4109: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE
nvd
CVE-2008-2949P3MEDIUMCVSS 6.8PoCv6v72008-06-30
CVE-2008-2949 [MEDIUM] CVE-2008-2949: Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of C
nvd
CVE-2005-1990P4MEDIUMCVSS 5.1PoCv5.01v5.52005-08-10
CVE-2005-1990 [MEDIUM] CVE-2005-1990: Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (applicatio Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll,
nvd
CVE-2010-3328P3HIGHCVSS 8.8v6v7+1 more2010-10-13
CVE-2010-3328 [HIGH] CWE-416 CVE-2010-3328: Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Inte Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2003-0701P3HIGHCVSS 7.5PoCv5.01v5.5+1 more2003-08-27
CVE-2003-0701 [HIGH] CVE-2003-0701: Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.
nvd
CVE-2012-0169P3CRITICALCVSS 9.3v92012-04-10
CVE-2012-0169 [CRITICAL] CWE-94 CVE-2012-0169: Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "JScript9 Remote Code Execution Vulnerability."
nvd
CVE-2014-1763P3CRITICALCVSS 10.0v9v10+1 more2014-04-27
CVE-2014-1763 [CRITICAL] CWE-399 CVE-2014-1763: Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2008-2948P3MEDIUMCVSS 6.8PoCv7v82008-06-30
CVE-2008-2948 [MEDIUM] CVE-2008-2948: Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of C
nvd
Microsoft Internet Explorer vulnerabilities | cvebase