Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 24 of 80
CVE-2014-4129P3CRITICALCVSS 9.3v82014-10-15
CVE-2014-4129 [CRITICAL] CWE-20 CVE-2014-4129: Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-1288P3CRITICALCVSS 9.3v82013-03-13
CVE-2013-1288 [CRITICAL] CWE-399 CVE-2013-1288: Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CTreeNode Use After Free Vulnerability."
nvd
CVE-2013-0094P3CRITICALCVSS 9.3v6v7+3 more2013-03-13
CVE-2013-0094 [CRITICAL] CWE-399 CVE-2013-0094: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer removeChild Use After Free Vulnerability."
nvd
CVE-2013-0093P3CRITICALCVSS 9.3v6v7+3 more2013-03-13
CVE-2013-0093 [CRITICAL] CWE-399 CVE-2013-0093: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer onBeforeCopy Use After Free Vulnerability."
nvd
CVE-2013-0087P3CRITICALCVSS 9.3v6v7+3 more2013-03-13
CVE-2013-0087 [CRITICAL] CWE-399 CVE-2013-0087: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer OnResize Use After Free Vulnerability."
nvd
CVE-2013-0089P3CRITICALCVSS 9.3v6v7+3 more2013-03-13
CVE-2013-0089 [CRITICAL] CWE-399 CVE-2013-0089: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkupBehaviorContext Use After Free Vulnerability."
nvd
CVE-2015-1767P3CRITICALCVSS 9.3v9v10+1 more2015-07-14
CVE-2015-1767 [CRITICAL] CWE-119 CVE-2015-1767: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2401 and CVE-2015-2408.
nvd
CVE-2015-6086P3MEDIUMCVSS 4.3PoCv9v10+1 more2015-11-11
CVE-2015-6086 [MEDIUM] CWE-200 CVE-2015-6086: Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information fro
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-2492P3CRITICALCVSS 9.3v7v8+3 more2015-09-09
CVE-2015-2492 [CRITICAL] CVE-2015-2492: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.
nvd
CVE-2015-2487P3CRITICALCVSS 9.3v7v8+3 more2015-09-09
CVE-2015-2487 [CRITICAL] CVE-2015-2487: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.
nvd
CVE-2015-2450P3CRITICALCVSS 9.3v9v10+1 more2015-08-14
CVE-2015-2450 [CRITICAL] CWE-119 CVE-2015-2450: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2451.
nvd
CVE-2015-2451P3CRITICALCVSS 9.3v9v10+1 more2015-08-14
CVE-2015-2451 [CRITICAL] CVE-2015-2451: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2450.
nvd
CVE-2008-0077P3HIGHCVSS 8.8v6v72008-02-12
CVE-2008-0077 [HIGH] CWE-416 CVE-2008-0077: Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote at
Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."
nvd
CVE-2009-0550P3CRITICALCVSS 9.3v5.01v6+1 more2009-04-15
CVE-2009-0550 [CRITICAL] CVE-2009-0550: Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 a
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remot
nvd
CVE-2004-0420P3CRITICALCVSS 10.0v6.0v6.0.2800.11062004-07-07
CVE-2004-0420 [CRITICAL] CVE-2004-0420: The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, a
The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.
nvd
CVE-2015-1745P3CRITICALCVSS 9.3v6v7+4 more2015-06-10
CVE-2015-1745 [CRITICAL] CVE-2015-1745: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1766.
nvd
CVE-2015-1747P3CRITICALCVSS 9.3v112015-06-10
CVE-2015-1747 [CRITICAL] CVE-2015-1747: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1742, CVE-2015-1750, and CVE-2015-1753.
nvd
CVE-2010-0489P3CRITICALCVSS 9.3v7v6+1 more2010-03-31
CVE-2010-0489 [CRITICAL] CWE-362 CVE-2010-0489: Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to e
Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."
nvd
CVE-2014-6330P3CRITICALCVSS 9.3v92014-12-11
CVE-2014-6330 [CRITICAL] CWE-119 CVE-2014-6330: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-6366P3CRITICALCVSS 9.3v6v72014-12-11
CVE-2014-6366 [CRITICAL] CWE-119 CVE-2014-6366: Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a den
Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd