cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 2 of 80
CVE-2013-7331P2MEDIUMCVSS 6.5KEVPoCRansomwarev6v7+4 more2014-02-26
CVE-2013-7331 [MEDIUM] CWE-200 CVE-2013-7331: The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.
nvd
CVE-2017-0059P2MEDIUMCVSS 4.3KEVPoCv9v10+1 more2017-03-17
CVE-2017-0059 [MEDIUM] CVE-2017-0059: Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.
nvd
CVE-2014-1776P1CRITICALCVSS 9.8KEVv6v7+4 more2014-04-27
CVE-2014-1776 [CRITICAL] CWE-416 CVE-2014-1776: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clari
nvd
CVE-2019-1367P1HIGHCVSS 7.5KEVRansomwarev10v11+1 more2019-09-23
CVE-2019-1367 [HIGH] CVE-2019-1367: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.
nvd
CVE-2018-8373P1HIGHCVSS 7.5KEVv11v10+1 more2018-08-15
CVE-2018-8373 [HIGH] CVE-2018-8373: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-837
nvd
CVE-2015-2425P1HIGHCVSS 8.8KEVv112015-07-14
CVE-2015-2425 [HIGH] CVE-2015-2425: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2384.
nvd
CVE-2015-2502P1HIGHCVSS 8.8KEVv7v8+3 more2015-08-19
CVE-2015-2502 [HIGH] CWE-787 CVE-2015-2502: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
nvd
CVE-2020-1380P1HIGHCVSS 8.8KEVv112020-08-17
CVE-2020-1380 [HIGH] CWE-787 CVE-2020-1380: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights a
nvd
CVE-2014-4123P1HIGHCVSS 8.8KEVv7v8+3 more2014-10-15
CVE-2014-4123 [HIGH] CVE-2014-4123: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.
nvd
CVE-2020-0968P1HIGHCVSS 7.5KEVRansomwarev11v92020-04-15
CVE-2020-0968 [HIGH] CWE-787 CVE-2020-0968: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.
nvd
CVE-2017-0222P1HIGHCVSS 8.8KEVv9v112017-05-12
CVE-2017-0222 [HIGH] CWE-787 CVE-2017-0222: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
nvd
CVE-2014-2817P1HIGHCVSS 8.8KEVv6v7+4 more2014-08-12
CVE-2014-2817 [HIGH] CVE-2014-2817: Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted we Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2017-0149P1HIGHCVSS 8.8KEVv9v10+1 more2017-03-17
CVE-2017-0149 [HIGH] CVE-2017-0149: Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
nvd
CVE-2016-3351P1MEDIUMCVSS 6.5KEVRansomwarev9v10+1 more2016-09-14
CVE-2016-3351 [MEDIUM] CVE-2016-3351: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensiti Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2021-27085P1HIGHCVSS 8.8KEVv112021-03-11
CVE-2021-27085 [HIGH] CVE-2021-27085: Internet Explorer Remote Code Execution Vulnerability Internet Explorer Remote Code Execution Vulnerability
nvd
CVE-2016-3298P1MEDIUMCVSS 6.5KEVRansomwarev9v10+1 more2016-10-14
CVE-2016-3298 [MEDIUM] CVE-2016-3298: Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Window Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2017-0210P1HIGHCVSS 8.8KEVv10v112017-04-12
CVE-2017-0210 [HIGH] CVE-2017-0210: An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cros An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2020-0878P1HIGHCVSS 7.5KEVRansomwarev11v92020-09-11
CVE-2020-0878 [HIGH] CWE-787 CVE-2020-0878: <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
nvd
CVE-2018-8653P2HIGHCVSS 7.5KEVv9v10+1 more2018-12-20
CVE-2018-8653 [HIGH] CVE-2018-8653: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.
nvd
CVE-2015-0071P2MEDIUMCVSS 6.5KEVv9v10+1 more2015-02-11
CVE-2015-0071 [MEDIUM] CVE-2015-0071: Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mecha Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase