cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 22 of 80
CVE-2009-1917P3CRITICALCVSS 9.3v6v7+2 more2009-07-29
CVE-2009-1917 [CRITICAL] CWE-399 CVE-2009-1917: Microsoft Internet Explorer 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP Microsoft Internet Explorer 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory, which allows remote attackers to execute arbitrar
nvd
CVE-2012-1538P3CRITICALCVSS 9.3v92012-11-14
CVE-2012-1538 [CRITICAL] CWE-399 CVE-2012-1538: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CFormElement Use After Free Vulnerability."
nvd
CVE-2016-3297P3HIGHCVSS 8.8v9v10+1 more2016-09-14
CVE-2016-3297 [HIGH] CVE-2016-3297: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2011-1998P3CRITICALCVSS 9.3v92011-10-12
CVE-2011-1998 [CRITICAL] CWE-908 CVE-2011-1998: Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "Jscript9.dll Remote Code Execution Vulnerability."
nvd
CVE-2012-1524P3CRITICALCVSS 9.3v92012-07-10
CVE-2012-1524 [CRITICAL] CWE-94 CVE-2012-1524: Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Attribute Remove Remote Code Execution Vulnerability."
nvd
CVE-2013-1308P3CRITICALCVSS 9.3v6v7+3 more2013-05-15
CVE-2013-1308 [CRITICAL] CWE-416 CVE-2013-1308: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1309 and CVE-2013-2551.
nvd
CVE-2014-4143P3CRITICALCVSS 9.3v6v7+4 more2014-11-11
CVE-2014-4143 [CRITICAL] CWE-399 CVE-2014-4143: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6341.
nvd
CVE-2012-2521P3CRITICALCVSS 9.3v6v7+2 more2012-08-15
CVE-2012-2521 [CRITICAL] CWE-94 CVE-2012-2521: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Asynchronous NULL Object Access Remote Code Execution Vulnerability."
nvd
CVE-2015-2408P3CRITICALCVSS 9.3v9v10+1 more2015-07-14
CVE-2015-2408 [CRITICAL] CVE-2015-2408: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2401.
nvd
CVE-2015-0037P3CRITICALCVSS 9.3v112015-02-11
CVE-2015-0037 [CRITICAL] CVE-2015-0037: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0040, and CVE-2015-0066.
nvd
CVE-2008-4259P3CRITICALCVSS 9.3v5.01v6+1 more2008-12-10
CVE-2008-4259 [CRITICAL] CWE-399 CVE-2008-4259: Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which all Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file with a long name, aka "HTML Objects Memory Corruption Vulnerability."
nvd
CVE-2013-1307P3CRITICALCVSS 9.3v8v92013-05-15
CVE-2013-1307 [CRITICAL] CVE-2013-1307: Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execu Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-0811.
nvd
CVE-2013-0811P3CRITICALCVSS 9.3v8v92013-05-15
CVE-2013-0811 [CRITICAL] CWE-416 CVE-2013-0811: Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execu Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1307.
nvd
CVE-2013-1338P3CRITICALCVSS 9.3v6v7+3 more2013-05-02
CVE-2013-1338 [CRITICAL] CVE-2013-1338: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1303 and CVE-2013-1304.
nvd
CVE-2013-1303P3CRITICALCVSS 9.3v6v7+3 more2013-04-09
CVE-2013-1303 [CRITICAL] CWE-399 CVE-2013-1303: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1304 and CVE-2013-1338.
nvd
CVE-2004-0216P3CRITICALCVSS 10.0v5.01v5.52004-11-03
CVE-2004-0216 [CRITICAL] CVE-2004-0216: Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows re Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.
nvd
CVE-2015-2542P3CRITICALCVSS 9.3v10v112015-09-09
CVE-2015-2542 [CRITICAL] CWE-119 CVE-2015-2542: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."
nvd
CVE-2016-0061P3HIGHCVSS 8.8v9v10+1 more2016-02-10
CVE-2016-0061 [HIGH] CVE-2016-0061: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072.
nvd
CVE-2016-0062P3HIGHCVSS 8.8v112016-02-10
CVE-2016-0062 [HIGH] CWE-119 CVE-2016-0062: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2013-0018P3CRITICALCVSS 9.3v6v7+2 more2013-02-13
CVE-2013-0018 [CRITICAL] CWE-399 CVE-2013-0018: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to e Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SetCapture Use After Free Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase