cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 21 of 80
CVE-2015-2443P3CRITICALCVSS 9.3v10v112015-08-14
CVE-2015-2443 [CRITICAL] CWE-119 CVE-2015-2443: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."
nvd
CVE-2008-4261P3CRITICALCVSS 9.3v5.01v6+1 more2008-12-10
CVE-2008-4261 [CRITICAL] CWE-399 CVE-2008-4261: Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Me
nvd
CVE-2016-3204P3HIGHCVSS 8.8v9v10+1 more2016-07-13
CVE-2016-3204 [HIGH] CWE-119 CVE-2016-3204: The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explor The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2010-3346P3CRITICALCVSS 9.3v6v7+1 more2010-12-16
CVE-2010-3346 [CRITICAL] CWE-908 CVE-2010-3346: Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows rem Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
nvd
CVE-2010-3343P3CRITICALCVSS 9.3v62010-12-16
CVE-2010-3343 [CRITICAL] CWE-908 CVE-2010-3343: Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
nvd
CVE-2010-3345P3CRITICALCVSS 9.3v82010-12-16
CVE-2010-3345 [CRITICAL] CWE-908 CVE-2010-3345: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
nvd
CVE-2012-4787P3CRITICALCVSS 9.0v9v102012-12-12
CVE-2012-4787 [CRITICAL] CWE-399 CVE-2012-4787: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to exec Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "Improper Ref Counting Use After Free Vulnerability."
nvd
CVE-2014-4089P3CRITICALCVSS 9.3v10v112014-09-10
CVE-2014-4089 [CRITICAL] CVE-2014-4089: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4091, and CVE-2014-4102.
nvd
CVE-2009-0552P3CRITICALCVSS 9.3v5.0.1v62009-04-15
CVE-2009-0552 [CRITICAL] CWE-94 CVE-2009-0552: Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulner
nvd
CVE-2015-1623P3CRITICALCVSS 9.3v112015-03-11
CVE-2015-1623 [CRITICAL] CVE-2015-1623: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0056 and CVE-2015-1626.
nvd
CVE-2014-6351P3CRITICALCVSS 9.3v8v9+2 more2014-11-11
CVE-2014-6351 [CRITICAL] CWE-399 CVE-2014-6351: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2010-0267P3CRITICALCVSS 9.3v7v62010-03-31
CVE-2010-0267 [CRITICAL] CWE-94 CVE-2010-0267: Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2012-1878P3CRITICALCVSS 9.3v6v7+2 more2012-06-12
CVE-2012-1878 [CRITICAL] CWE-94 CVE-2012-1878: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnBeforeDeactivate Event Remote Code Execution Vulnerability."
nvd
CVE-2015-0032P3CRITICALCVSS 9.3v8v9+2 more2015-03-11
CVE-2015-0032 [CRITICAL] CWE-399 CVE-2015-0032: vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."
nvd
CVE-2001-1325P4HIGHCVSS 7.5PoCv5.0v5.52001-04-20
CVE-2001-1325 [HIGH] CVE-2001-1325: Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute sc Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).
nvd
CVE-2009-1141P3CRITICALCVSS 9.3v62009-06-10
CVE-2009-1141 [CRITICAL] CWE-399 CVE-2009-1141: Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vul
nvd
CVE-2010-2559P3CRITICALCVSS 9.3v82010-08-11
CVE-2010-2559 [CRITICAL] CVE-2010-2559: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, CVE-2
nvd
CVE-2009-1917P3CRITICALCVSS 9.3v6v7+2 more2009-07-29
CVE-2009-1917 [CRITICAL] CWE-399 CVE-2009-1917: Microsoft Internet Explorer 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP Microsoft Internet Explorer 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory, which allows remote attackers to execute arbitrar
nvd
CVE-2012-1538P3CRITICALCVSS 9.3v92012-11-14
CVE-2012-1538 [CRITICAL] CWE-399 CVE-2012-1538: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CFormElement Use After Free Vulnerability."
nvd
CVE-2016-3297P3HIGHCVSS 8.8v9v10+1 more2016-09-14
CVE-2016-3297 [HIGH] CVE-2016-3297: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase