Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 18 of 80
CVE-2013-0022P3CRITICALCVSS 9.0v92013-02-13
CVE-2013-0022 [CRITICAL] CWE-399 CVE-2013-0022: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability."
nvd
CVE-2016-3248P3HIGHCVSS 8.8v9v10+1 more2016-07-13
CVE-2016-3248 [HIGH] CWE-119 CVE-2016-3248: The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft I
The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a differen
nvd
CVE-2012-0171P3CRITICALCVSS 9.3v6v7+2 more2012-04-10
CVE-2012-0171 [CRITICAL] CWE-94 CVE-2012-0171: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "SelectAll Remote Code Execution Vulnerability."
nvd
CVE-2010-1262P3CRITICALCVSS 9.3v8v6+1 more2010-06-08
CVE-2010-1262 [CRITICAL] CWE-94 CVE-2010-1262: Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary cod
Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."
nvd
CVE-2016-0060P3HIGHCVSS 8.8v9v10+1 more2016-02-10
CVE-2016-0060 [HIGH] CWE-119 CVE-2016-0060: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0061, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072.
nvd
CVE-2006-3637P4MEDIUMCVSS 5.1PoCv5.012006-08-08
CVE-2006-3637 [MEDIUM] CVE-2006-3637: Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component co
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
nvd
CVE-2009-1529P3HIGHCVSS 8.1v6v7+2 more2009-06-10
CVE-2009-1529 [HIGH] CWE-399 CVE-2009-1529: Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, S
Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by calling the setCapture method on a collection of crafted objects, aka "Uninitialized Memory Corruption Vulnerabil
nvd
CVE-2014-4081P3CRITICALCVSS 9.3v6v7+4 more2014-09-10
CVE-2014-4081 [CRITICAL] CVE-2014-4081: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE
nvd
CVE-2014-0288P3CRITICALCVSS 9.3v9v10+1 more2014-02-12
CVE-2014-0288 [CRITICAL] CVE-2014-0288: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0274.
nvd
CVE-2014-0286P3CRITICALCVSS 9.3v6v7+4 more2014-02-12
CVE-2014-0286 [CRITICAL] CVE-2014-0286: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0285.
nvd
CVE-2014-0270P3CRITICALCVSS 9.3v9v10+1 more2014-02-12
CVE-2014-0270 [CRITICAL] CWE-119 CVE-2014-0270: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0273, CVE-2014-0274, and CVE-2014-0288.
nvd
CVE-2009-2502P3HIGHCVSS 8.1v62009-10-14
CVE-2009-2502 [HIGH] CWE-119 CVE-2009-2502: Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3,
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, an
nvd
CVE-2014-0290P3CRITICALCVSS 9.3v112014-02-12
CVE-2014-0290 [CRITICAL] CVE-2014-0290: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0267 and CVE-2014-0289.
nvd
CVE-2014-0285P3CRITICALCVSS 9.3v6v7+4 more2014-02-12
CVE-2014-0285 [CRITICAL] CVE-2014-0285: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0286.
nvd
CVE-2008-1086P3CRITICALCVSS 9.3v5.01v62008-04-08
CVE-2008-1086 [CRITICAL] CWE-94 CVE-2008-1086: The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1,
The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
nvd
CVE-2012-2522P3CRITICALCVSS 9.3v6v7+2 more2012-08-15
CVE-2012-2522 [CRITICAL] CWE-94 CVE-2012-2522: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a malformed virtual function table after this table's deletion, aka "Virtual Function Table Corruption Remote Code Execution Vulnerability."
nvd
CVE-2012-1880P3CRITICALCVSS 9.3v7v8+2 more2012-06-12
CVE-2012-1880 [CRITICAL] CWE-94 CVE-2012-1880: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "insertRow Remote Code Execution Vulnerability."
nvd
CVE-2002-0647P4HIGHCVSS 7.5PoCv5.01v5.5+1 more2002-09-24
CVE-2002-0647 [HIGH] CVE-2002-0647: Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft In
Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".
nvd
CVE-2015-2498P3CRITICALCVSS 9.3v7v8+3 more2015-09-09
CVE-2015-2498 [CRITICAL] CVE-2015-2498: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, and CVE-2015-2499.
nvd
CVE-2015-2499P3CRITICALCVSS 9.3v7v8+3 more2015-09-09
CVE-2015-2499 [CRITICAL] CVE-2015-2499: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, and CVE-2015-2498.
nvd