Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 20 of 80
CVE-2012-4775P3HIGHCVSS 8.8v92012-11-14
CVE-2012-4775 [HIGH] CWE-399 CVE-2012-4775: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CTreeNode Use After Free Vulnerability."
nvd
CVE-2013-0021P3CRITICALCVSS 9.3v6v7+3 more2013-02-13
CVE-2013-0021 [CRITICAL] CWE-399 CVE-2013-0021: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer vtable Use After Free Vulnerability."
nvd
CVE-2002-0980P4HIGHCVSS 7.5PoCv5.5v6.02002-09-24
CVE-2002-0980 [HIGH] CVE-2002-0980: The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known locati
The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.
nvd
CVE-2010-1262P3CRITICALCVSS 9.3v8v6+1 more2010-06-08
CVE-2010-1262 [CRITICAL] CWE-94 CVE-2010-1262: Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary cod
Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."
nvd
CVE-2012-1522P3CRITICALCVSS 9.3v92012-07-10
CVE-2012-1522 [CRITICAL] CWE-94 CVE-2012-1522: Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attack
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Cached Object Remote Code Execution Vulnerability."
nvd
CVE-2008-1442P3CRITICALCVSS 9.3v6v72008-06-12
CVE-2008-1442 [CRITICAL] CWE-119 CVE-2008-1442: Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows
Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Objects Memory Corruption Vulnerability."
nvd
CVE-2015-1714P3CRITICALCVSS 9.3v10v112015-05-13
CVE-2015-1714 [CRITICAL] CWE-119 CVE-2015-1714: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-1712P3CRITICALCVSS 9.3v8v92015-05-13
CVE-2015-1712 [CRITICAL] CVE-2015-1712: Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a den
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1691.
nvd
CVE-2013-1310P3CRITICALCVSS 9.3v6v72013-05-15
CVE-2013-1310 [CRITICAL] CWE-416 CVE-2013-1310: Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execu
Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."
nvd
CVE-2013-1312P3CRITICALCVSS 9.3v9v102013-05-15
CVE-2013-1312 [CRITICAL] CWE-416 CVE-2013-1312: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to exec
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."
nvd
CVE-2014-0299P3CRITICALCVSS 9.3v6v7+4 more2014-03-12
CVE-2014-0299 [CRITICAL] CWE-119 CVE-2014-0299: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0305 and CVE-2014-0311.
nvd
CVE-2014-6329P3CRITICALCVSS 9.3v112014-12-11
CVE-2014-6329 [CRITICAL] CVE-2014-6329: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6327 and CVE-2014-6376.
nvd
CVE-2006-2382P3CRITICALCVSS 10.0v5.01v62006-06-13
CVE-2006-2382 [CRITICAL] CWE-119 CVE-2006-2382: Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remo
Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."
nvd
CVE-2007-0942P3CRITICALCVSS 9.3v5.0.1v6.0+1 more2007-05-08
CVE-2007-0942 [CRITICAL] CVE-2007-0942: Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Wind
Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls," which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.
nvd
CVE-2013-0029P3HIGHCVSS 7.5v9v7+2 more2013-02-13
CVE-2013-0029 [HIGH] CWE-399 CVE-2013-0029: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to e
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CHTML Use After Free Vulnerability."
nvd
CVE-2014-0287P3CRITICALCVSS 9.3v8v9+2 more2014-02-12
CVE-2014-0287 [CRITICAL] CVE-2014-0287: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0281.
nvd
CVE-2014-4080P3CRITICALCVSS 9.3v10v112014-09-10
CVE-2014-4080 [CRITICAL] CWE-119 CVE-2014-4080: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4089, CVE-2014-4091, and CVE-2014-4102.
nvd
CVE-2014-4101P3CRITICALCVSS 9.3v112014-09-10
CVE-2014-4101 [CRITICAL] CVE-2014-4101: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4087, CVE-2014-4095, and CVE-2014-4096.
nvd
CVE-2016-0200P3HIGHCVSS 8.8v9v10+1 more2016-06-16
CVE-2016-0200 [HIGH] CVE-2016-0200: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0199 and CVE-2016-3211.
nvd
CVE-2014-1777P3MEDIUMCVSS 4.3PoCv10v112014-06-11
CVE-2014-1777 [MEDIUM] CWE-200 CVE-2014-1777: Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via
Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd