cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 23 of 80
CVE-2013-0026P3CRITICALCVSS 9.3v92013-02-13
CVE-2013-0026 [CRITICAL] CWE-399 CVE-2013-0026: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer InsertElement Use After Free Vulnerability."
nvd
CVE-2013-0088P3CRITICALCVSS 9.3v6v7+3 more2013-03-13
CVE-2013-0088 [CRITICAL] CWE-399 CVE-2013-0088: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer saveHistory Use After Free Vulnerability."
nvd
CVE-2013-0091P3CRITICALCVSS 9.3v82013-03-13
CVE-2013-0091 [CRITICAL] CWE-399 CVE-2013-0091: Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CElement Use After Free Vulnerability."
nvd
CVE-2015-6159P3CRITICALCVSS 9.3v112015-12-09
CVE-2015-6159 [CRITICAL] CVE-2015-6159: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6158, and CVE-2015-6160.
nvd
CVE-2012-4782P3CRITICALCVSS 9.3v9v102012-12-12
CVE-2012-4782 [CRITICAL] CWE-399 CVE-2012-4782: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to exec Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "CMarkup Use After Free Vulnerability."
nvd
CVE-2012-2557P3CRITICALCVSS 9.3v6v7+2 more2012-09-21
CVE-2012-2557 [CRITICAL] CWE-399 CVE-2012-2557: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to e Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "cloneNode Use After Free Vulnerability."
nvd
CVE-2012-2548P3CRITICALCVSS 9.3v92012-09-21
CVE-2012-2548 [CRITICAL] CWE-399 CVE-2012-2548: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Layout Use After Free Vulnerability."
nvd
CVE-2016-0072P3HIGHCVSS 8.8v9v10+1 more2016-02-10
CVE-2016-0072 [HIGH] CVE-2016-0072: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0063, and CVE-2016-0067.
nvd
CVE-2015-6065P3CRITICALCVSS 9.3v9v10+1 more2015-11-11
CVE-2015-6065 [CRITICAL] CWE-119 CVE-2015-6065: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6078.
nvd
CVE-2015-6081P3CRITICALCVSS 9.3v8v9+2 more2015-11-11
CVE-2015-6081 [CRITICAL] CVE-2015-6081: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6069.
nvd
CVE-2015-2541P3CRITICALCVSS 9.3v9v10+1 more2015-09-09
CVE-2015-2541 [CRITICAL] CVE-2015-2541: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2485 and CVE-2015-2491.
nvd
CVE-2010-3340P3CRITICALCVSS 9.3v6v72010-12-16
CVE-2010-3340 [CRITICAL] CWE-94 CVE-2010-3340: Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
nvd
CVE-2002-0023P4MEDIUMCVSS 5.0PoCv5.01v5.5+1 more2002-03-08
CVE-2002-0023 [MEDIUM] CVE-2002-0023: Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed re Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.
nvd
CVE-2015-0042P3CRITICALCVSS 9.3v9v10+1 more2015-02-11
CVE-2015-0042 [CRITICAL] CVE-2015-0042: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0038 and CVE-2015-0046.
nvd
CVE-2018-0891P3MEDIUMCVSS 4.3PoCv9v10+1 more2018-03-14
CVE-2018-0891 [MEDIUM] CWE-401 CVE-2018-0891: ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Window ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow information disclosure, due to how the scripting engine handles objects in memory, a
nvd
CVE-2015-6083P3CRITICALCVSS 9.3v8v9+2 more2015-12-09
CVE-2015-6083 [CRITICAL] CWE-119 CVE-2015-6083: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6151.
nvd
CVE-2015-6150P3CRITICALCVSS 9.3v7v8+3 more2015-12-09
CVE-2015-6150 [CRITICAL] CWE-119 CVE-2015-6150: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6154.
nvd
CVE-2015-2441P3CRITICALCVSS 9.3v7v8+3 more2015-08-14
CVE-2015-2441 [CRITICAL] CWE-119 CVE-2015-2441: Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to execute arbitrary code o Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2452.
nvd
CVE-2014-6369P3CRITICALCVSS 9.3v9v10+1 more2014-12-11
CVE-2014-6369 [CRITICAL] CWE-20 CVE-2014-6369: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-0023P3CRITICALCVSS 9.3v10v92013-02-13
CVE-2013-0023 [CRITICAL] CWE-399 CVE-2013-0023: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to exec Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CDispNode Use After Free Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase