Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
40
actively exploited
Public exploits
364
Exploited in wild
48
Severity breakdown
CRITICAL690HIGH450MEDIUM404LOW50

Vulnerabilities

Page 25 of 80
CVE-2015-2404CRITICALCVSS 9.3v6v7+4 more2015-07-14
CVE-2015-2404 [CRITICAL] CVE-2015-2404: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2406, and CVE-2015-2422.
nvd
CVE-2015-1767CRITICALCVSS 9.3v9v10+1 more2015-07-14
CVE-2015-1767 [CRITICAL] CWE-119 CVE-2015-1767: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2401 and CVE-2015-2408.
nvd
CVE-2015-2408CRITICALCVSS 9.3v9v10+1 more2015-07-14
CVE-2015-2408 [CRITICAL] CVE-2015-2408: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2401.
nvd
CVE-2015-2391CRITICALCVSS 9.3v92015-07-14
CVE-2015-2391 [CRITICAL] CWE-119 CVE-2015-2391: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-2425HIGHCVSS 8.8KEVv112015-07-14
CVE-2015-2425 [HIGH] CVE-2015-2425: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2384.
nvd
CVE-2015-2419HIGHCVSS 8.8KEVPoCv10v112015-07-14
CVE-2015-2419 [HIGH] CWE-787 CVE-2015-2419: JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
nvd
CVE-2015-2413MEDIUMCVSS 4.3v6v7+4 more2015-07-14
CVE-2015-2413 [MEDIUM] CWE-200 CVE-2015-2413: Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-1729MEDIUMCVSS 4.3v9v10+1 more2015-07-14
CVE-2015-1729 [MEDIUM] CWE-200 CVE-2015-1729: Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1 Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-2421MEDIUMCVSS 4.3v6v7+4 more2015-07-14
CVE-2015-2421 [MEDIUM] CWE-200 CVE-2015-2421: Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mecha Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."
nvd
CVE-2015-2414MEDIUMCVSS 4.3v8v9+2 more2015-07-14
CVE-2015-2414 [MEDIUM] CWE-200 CVE-2015-2414: Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-histor Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-2412MEDIUMCVSS 4.3v10v112015-07-14
CVE-2015-2412 [MEDIUM] CWE-20 CVE-2015-2412: Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a cr Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-2402MEDIUMCVSS 4.3v7v8+3 more2015-07-14
CVE-2015-2402 [MEDIUM] CWE-264 CVE-2015-2402: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2015-2410MEDIUMCVSS 4.3v6v7+4 more2015-07-14
CVE-2015-2410 [MEDIUM] CWE-200 CVE-2015-2410: Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted stylesheet, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-2398MEDIUMCVSS 4.3v8v9+2 more2015-07-14
CVE-2015-2398 [MEDIUM] CWE-79 CVE-2015-2398: Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a craf Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability."
nvd
CVE-2015-1744CRITICALCVSS 9.3v6v7+4 more2015-06-10
CVE-2015-1744 [CRITICAL] CVE-2015-1744: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1745, and CVE-2015-1766.
nvd
CVE-2015-1730CRITICALCVSS 9.3PoCv92015-06-10
CVE-2015-1730 [CRITICAL] CWE-399 CVE-2015-1730: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-1687CRITICALCVSS 9.3v6v7+2 more2015-06-10
CVE-2015-1687 [CRITICAL] CWE-19 CVE-2015-1687: Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-1766CRITICALCVSS 9.3v6v7+4 more2015-06-10
CVE-2015-1766 [CRITICAL] CVE-2015-1766: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.
nvd
CVE-2015-1741CRITICALCVSS 9.3v9v10+1 more2015-06-10
CVE-2015-1741 [CRITICAL] CWE-399 CVE-2015-1741: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1752.
nvd
CVE-2015-1754CRITICALCVSS 9.3v82015-06-10
CVE-2015-1754 [CRITICAL] CWE-399 CVE-2015-1754: Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd