Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 17 of 80
CVE-2018-1004P3HIGHCVSS 8.8v92018-04-12
CVE-2018-1004 [HIGH] CWE-787 CVE-2018-1004: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.
nvd
CVE-2009-1532P3HIGHCVSS 8.8v82009-06-10
CVE-2009-1532 [HIGH] CWE-787 CVE-2009-1532: Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, S
Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, SP1, and SP2; and 8 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via "malformed row property references" that trigger an access of an object that (1) was not properly initialized or
nvd
CVE-2004-2291P3HIGHCVSS 7.5PoCv5.5v6.02004-12-31
CVE-2004-2291 [HIGH] CVE-2004-2291: Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code vi
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.
nvd
CVE-2006-7206P3HIGHCVSS 7.8PoCv62007-06-22
CVE-2006-7206 [HIGH] CVE-2006-7206: Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.
nvd
CVE-2014-0289P3CRITICALCVSS 9.3v112014-02-12
CVE-2014-0289 [CRITICAL] CVE-2014-0289: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0267 and CVE-2014-0290.
nvd
CVE-2013-0092P3CRITICALCVSS 9.3v6v7+3 more2013-03-13
CVE-2013-0092 [CRITICAL] CWE-399 CVE-2013-0092: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer GetMarkupPtr Use After Free Vulnerability."
nvd
CVE-2009-1530P3CRITICALCVSS 9.3v6v7+2 more2009-06-10
CVE-2009-1530 [CRITICAL] CWE-399 CVE-2009-1530: Use-after-free vulnerability in Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Serv
Use-after-free vulnerability in Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that (1) was not proper
nvd
CVE-2009-2504P3CRITICALCVSS 9.3v62009-10-14
CVE-2009-2504 [CRITICAL] CWE-189 CVE-2009-2504: Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Fra
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word
nvd
CVE-2011-1347P3HIGHCVSS 8.8v82011-03-10
CVE-2011-1347 [HIGH] CVE-2011-1347: Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to b
Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
nvd
CVE-2013-0030P3CRITICALCVSS 9.3v6v7+3 more2013-02-13
CVE-2013-0030 [CRITICAL] CWE-119 CVE-2013-0030: The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not
The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka "VML Memory Corruption Vulnerability."
nvd
CVE-2008-3475P3HIGHCVSS 8.8v5.01v6+1 more2008-10-15
CVE-2008-3475 [HIGH] CWE-908 CVE-2008-3475: Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoin
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2000-0061P3CRITICALCVSS 10.0PoCv4.0v4.0.1+3 more2000-01-07
CVE-2000-0061 [CRITICAL] CVE-2000-0061: Internet Explorer 5 does not modify the security zone for a document that is being loaded into a win
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.
nvd
CVE-2009-1043P3CRITICALCVSS 10.0v82009-03-23
CVE-2009-1043 [CRITICAL] CVE-2009-1043: Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to e
Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
nvd
CVE-2007-1751P3CRITICALCVSS 9.3v5.01v6+1 more2007-06-12
CVE-2007-1751 [CRITICAL] CWE-908 CVE-2007-1751: Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by caus
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2013-3140P3CRITICALCVSS 9.3v92013-12-16
CVE-2013-3140 [CRITICAL] CWE-399 CVE-2013-3140: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted CMarkup object, aka "Internet Explorer Use After Free Vulnerability."
nvd
CVE-2012-1877P3CRITICALCVSS 9.3v6v7+2 more2012-06-12
CVE-2012-1877 [CRITICAL] CWE-94 CVE-2012-1877: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Title Element Change Remote Code Execution Vulnerability."
nvd
CVE-2016-0069P3HIGHCVSS 8.8v9v10+1 more2016-02-18
CVE-2016-0069 [HIGH] CVE-2016-0069: Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy vi
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0068.
nvd
CVE-2016-0188P3HIGHCVSS 8.8v112016-05-11
CVE-2016-0188 [HIGH] CWE-284 CVE-2016-0188: The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11
The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11 allows remote attackers to bypass a code-signing protection mechanism via unspecified vectors, aka "Internet Explorer Security Feature Bypass."
nvd
CVE-2011-1995P3CRITICALCVSS 9.3v6v7+2 more2011-10-12
CVE-2011-1995 [CRITICAL] CWE-908 CVE-2011-1995: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability."
nvd
CVE-2013-0020P3CRITICALCVSS 9.3v92013-02-13
CVE-2013-0020 [CRITICAL] CWE-399 CVE-2013-0020: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkup Use After Free Vulnerability."
nvd