cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 21 of 80
CVE-2014-0281P3CRITICALCVSS 9.3v8v9+2 more2014-02-12
CVE-2014-0281 [CRITICAL] CWE-119 CVE-2014-0281: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0287.
nvd
CVE-2013-1451P3MEDIUMCVSS 4.0PoCv8v92013-01-29
CVE-2013-1451 [MEDIUM] CVE-2013-1451: Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy addres Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for remote attackers to spoof web sites via a crafted HTML document that triggers many HTTPS requests to an arbitrary
nvd
CVE-2012-1874P3CRITICALCVSS 9.3v8v92012-06-12
CVE-2012-1874 [CRITICAL] CWE-94 CVE-2012-1874: Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows user-as Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows user-assisted remote attackers to execute arbitrary code by accessing a deleted object, aka "Developer Toolbar Remote Code Execution Vulnerability."
nvd
CVE-2012-1881P3CRITICALCVSS 9.3v8v92012-06-12
CVE-2012-1881 [CRITICAL] CWE-94 CVE-2012-1881: Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnRowsInserted Event Remote Code Execution Vulnerability."
nvd
CVE-2015-2447P3CRITICALCVSS 9.3v112015-08-14
CVE-2015-2447 [CRITICAL] CVE-2015-2447: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2446.
nvd
CVE-2015-2501P3CRITICALCVSS 9.3v92015-09-09
CVE-2015-2501 [CRITICAL] CWE-119 CVE-2015-2501: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."
nvd
CVE-2015-2500P3CRITICALCVSS 9.3v7v82015-09-09
CVE-2015-2500 [CRITICAL] CWE-119 CVE-2015-2500: Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a den Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."
nvd
CVE-2015-2443P3CRITICALCVSS 9.3v10v112015-08-14
CVE-2015-2443 [CRITICAL] CWE-119 CVE-2015-2443: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."
nvd
CVE-2008-4261P3CRITICALCVSS 9.3v5.01v6+1 more2008-12-10
CVE-2008-4261 [CRITICAL] CWE-399 CVE-2008-4261: Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Me
nvd
CVE-2016-3204P3HIGHCVSS 8.8v9v10+1 more2016-07-13
CVE-2016-3204 [HIGH] CWE-119 CVE-2016-3204: The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explor The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2010-3346P3CRITICALCVSS 9.3v6v7+1 more2010-12-16
CVE-2010-3346 [CRITICAL] CWE-908 CVE-2010-3346: Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows rem Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
nvd
CVE-2010-3345P3CRITICALCVSS 9.3v82010-12-16
CVE-2010-3345 [CRITICAL] CWE-908 CVE-2010-3345: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
nvd
CVE-2014-4089P3CRITICALCVSS 9.3v10v112014-09-10
CVE-2014-4089 [CRITICAL] CVE-2014-4089: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4091, and CVE-2014-4102.
nvd
CVE-2015-1623P3CRITICALCVSS 9.3v112015-03-11
CVE-2015-1623 [CRITICAL] CVE-2015-1623: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0056 and CVE-2015-1626.
nvd
CVE-2010-0267P3CRITICALCVSS 9.3v7v62010-03-31
CVE-2010-0267 [CRITICAL] CWE-94 CVE-2010-0267: Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2012-1878P3CRITICALCVSS 9.3v6v7+2 more2012-06-12
CVE-2012-1878 [CRITICAL] CWE-94 CVE-2012-1878: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnBeforeDeactivate Event Remote Code Execution Vulnerability."
nvd
CVE-2015-0032P3CRITICALCVSS 9.3v8v9+2 more2015-03-11
CVE-2015-0032 [CRITICAL] CWE-399 CVE-2015-0032: vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."
nvd
CVE-2001-1325P4HIGHCVSS 7.5PoCv5.0v5.52001-04-20
CVE-2001-1325 [HIGH] CVE-2001-1325: Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute sc Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).
nvd
CVE-2009-1141P3CRITICALCVSS 9.3v62009-06-10
CVE-2009-1141 [CRITICAL] CWE-399 CVE-2009-1141: Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vul
nvd
CVE-2010-2559P3CRITICALCVSS 9.3v82010-08-11
CVE-2010-2559 [CRITICAL] CVE-2010-2559: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, CVE-2
nvd
Microsoft Internet Explorer vulnerabilities | cvebase