Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 19 of 80
CVE-2014-0274P3CRITICALCVSS 9.3v9v10+1 more2014-02-12
CVE-2014-0274 [CRITICAL] CVE-2014-0274: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0288.
nvd
CVE-2014-4063P3CRITICALCVSS 9.3v6v7+4 more2014-08-12
CVE-2014-4063 [CRITICAL] CVE-2014-4063: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2826, and CVE-2014-2827.
nvd
CVE-2014-2804P3CRITICALCVSS 9.3v8v9+2 more2014-07-08
CVE-2014-2804 [CRITICAL] CVE-2014-2804: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2798.
nvd
CVE-2014-0273P3CRITICALCVSS 9.3v9v10+1 more2014-02-12
CVE-2014-0273 [CRITICAL] CVE-2014-0273: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0274, and CVE-2014-0288.
nvd
CVE-2014-0275P3CRITICALCVSS 9.3v6v7+4 more2014-02-12
CVE-2014-0275 [CRITICAL] CWE-119 CVE-2014-0275: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0285 and CVE-2014-0286.
nvd
CVE-2014-4094P3CRITICALCVSS 9.3v6v7+4 more2014-09-10
CVE-2014-4094 [CRITICAL] CVE-2014-4094: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE
nvd
CVE-2012-1523P3CRITICALCVSS 9.3v6v7+1 more2012-06-12
CVE-2012-1523 [CRITICAL] CWE-94 CVE-2012-1523: Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Center Element Remote Code Execution Vulnerability."
nvd
CVE-2012-1539P3HIGHCVSS 8.1v92012-11-14
CVE-2012-1539 [HIGH] CWE-399 CVE-2012-1539: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CTreePos Use After Free Vulnerability."
nvd
CVE-2012-0170P3CRITICALCVSS 9.3v6v72012-04-10
CVE-2012-0170 [CRITICAL] CWE-94 CVE-2012-0170: Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote
Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnReadyStateChange Remote Code Execution Vulnerability."
nvd
CVE-2012-2523P3CRITICALCVSS 9.3v8v92012-08-15
CVE-2012-2523 [CRITICAL] CWE-189 CVE-2012-2523: Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit pla
Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorrect size calculation during object copying, aka "JavaScript Integer Overflow Remote Code Execution Vulnerability."
nvd
CVE-2009-1919P3CRITICALCVSS 9.3v6v7+2 more2009-07-29
CVE-2009-1919 [CRITICAL] CWE-94 CVE-2009-1919: Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and S
Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory, which allows remote attackers to exec
nvd
CVE-2009-0551P3HIGHCVSS 8.1v6v72009-04-15
CVE-2009-0551 [HIGH] CWE-399 CVE-2009-0551: Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003
Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary
nvd
CVE-2012-0172P3CRITICALCVSS 9.3v6v7+1 more2012-04-10
CVE-2012-0172 [CRITICAL] CWE-94 CVE-2012-0172: Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Style Remote Code Execution Vulnerability."
nvd
CVE-2016-3260P3HIGHCVSS 8.8v112016-07-13
CVE-2016-3260 [HIGH] CWE-119 CVE-2016-3260: The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft I
The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2014-0297P3CRITICALCVSS 9.3v8v9+2 more2014-03-12
CVE-2014-0297 [CRITICAL] CWE-119 CVE-2014-0297: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0308, CVE-2014-0312, and CVE-2014-0324.
nvd
CVE-2014-0312P3CRITICALCVSS 9.3v8v9+2 more2014-03-12
CVE-2014-0312 [CRITICAL] CVE-2014-0312: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0324.
nvd
CVE-2012-0011P3CRITICALCVSS 9.3v7v8+1 more2012-02-14
CVE-2012-0011 [CRITICAL] CWE-94 CVE-2012-0011: Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "HTML Layout Remote Code Execution Vulnerability."
nvd
CVE-2014-4130P3CRITICALCVSS 9.3v112014-10-15
CVE-2014-4130 [CRITICAL] CWE-20 CVE-2014-4130: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4132 and CVE-2014-4138.
nvd
CVE-2012-4775P3HIGHCVSS 8.8v92012-11-14
CVE-2012-4775 [HIGH] CWE-399 CVE-2012-4775: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CTreeNode Use After Free Vulnerability."
nvd
CVE-2013-0021P3CRITICALCVSS 9.3v6v7+3 more2013-02-13
CVE-2013-0021 [CRITICAL] CWE-399 CVE-2013-0021: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer vtable Use After Free Vulnerability."
nvd