Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 27 of 80
CVE-2013-1307P3CRITICALCVSS 9.3v8v92013-05-15
CVE-2013-1307 [CRITICAL] CVE-2013-1307: Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execu
Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-0811.
nvd
CVE-2013-0811P3CRITICALCVSS 9.3v8v92013-05-15
CVE-2013-0811 [CRITICAL] CWE-416 CVE-2013-0811: Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execu
Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1307.
nvd
CVE-2013-1338P3CRITICALCVSS 9.3v6v7+3 more2013-05-02
CVE-2013-1338 [CRITICAL] CVE-2013-1338: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1303 and CVE-2013-1304.
nvd
CVE-2013-1303P3CRITICALCVSS 9.3v6v7+3 more2013-04-09
CVE-2013-1303 [CRITICAL] CWE-399 CVE-2013-1303: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1304 and CVE-2013-1338.
nvd
CVE-2009-2528P3CRITICALCVSS 9.3v62009-10-14
CVE-2009-2528 [CRITICAL] CWE-94 CVE-2009-2528: GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Ta
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
nvd
CVE-2015-2494P3CRITICALCVSS 9.3v7v8+3 more2015-09-09
CVE-2015-2494 [CRITICAL] CVE-2015-2494: Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2498, and CVE-2015-2499.
nvd
CVE-2015-2486P3CRITICALCVSS 9.3v7v8+3 more2015-09-09
CVE-2015-2486 [CRITICAL] CWE-119 CVE-2015-2486: Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.
nvd
CVE-2012-2546P3CRITICALCVSS 9.3v92012-09-21
CVE-2012-2546 [CRITICAL] CWE-399 CVE-2012-2546: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Event Listener Use After Free Vulnerability."
nvd
CVE-2012-1529P3CRITICALCVSS 9.3v8v92012-09-21
CVE-2012-1529 [CRITICAL] CWE-399 CVE-2012-1529: Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execu
Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "OnMove Use After Free Vulnerability."
nvd
CVE-2012-1526P3CRITICALCVSS 9.3v6v72012-08-15
CVE-2012-1526 [CRITICAL] CWE-119 CVE-2012-1526: Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote
Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability."
nvd
CVE-2013-1304P3CRITICALCVSS 9.3v6v7+3 more2013-04-09
CVE-2013-1304 [CRITICAL] CVE-2013-1304: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1303 and CVE-2013-1338.
nvd
CVE-2015-6064P3CRITICALCVSS 9.3v10v112015-11-11
CVE-2015-6064 [CRITICAL] CWE-119 CVE-2015-6064: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6084 and CVE-2015-6085.
nvd
CVE-2015-6151P3CRITICALCVSS 9.3v8v9+2 more2015-12-09
CVE-2015-6151 [CRITICAL] CVE-2015-6151: Microsoft Internet Explorer 8 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 8 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6083.
nvd
CVE-2015-6148P3CRITICALCVSS 9.3v9v10+1 more2015-12-09
CVE-2015-6148 [CRITICAL] CWE-119 CVE-2015-6148: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6156.
nvd
CVE-2015-1755P3CRITICALCVSS 9.3v10v112015-06-10
CVE-2015-1755 [CRITICAL] CVE-2015-1755: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1736, and CVE-2015-1737.
nvd
CVE-2016-0068P3HIGHCVSS 8.8v9v10+1 more2016-02-18
CVE-2016-0068 [HIGH] CWE-264 CVE-2016-0068: Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy vi
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.
nvd
CVE-2011-0036P3CRITICALCVSS 9.3v6v7+1 more2011-02-10
CVE-2011-0036 [CRITICAL] CVE-2011-0036: Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to a "dangling pointer," aka "Uninitialized Memory Corruption Vulnerability," a different vulnerabili
nvd
CVE-2011-0035P3CRITICALCVSS 9.3v6v7+1 more2011-02-10
CVE-2011-0035 [CRITICAL] CVE-2011-0035: Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-201
nvd
CVE-2015-0030P3CRITICALCVSS 9.3v6v7+4 more2015-02-11
CVE-2015-0030 [CRITICAL] CVE-2015-0030: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.
nvd
CVE-2015-6075P3CRITICALCVSS 9.3v112015-11-11
CVE-2015-6075 [CRITICAL] CVE-2015-6075: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072, CVE-2015-6073, CVE-2015-6077, CVE-2015-6079, CVE-2015-6080, and CVE-2015-6082.
nvd