Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 28 of 80
CVE-2015-6077P3CRITICALCVSS 9.3v112015-11-11
CVE-2015-6077 [CRITICAL] CVE-2015-6077: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072, CVE-2015-6073, CVE-2015-6075, CVE-2015-6079, CVE-2015-6080, and CVE-2015-6082.
nvd
CVE-2015-6076P3CRITICALCVSS 9.3v7v8+3 more2015-11-11
CVE-2015-6076 [CRITICAL] CVE-2015-6076: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6066, CVE-2015-6070, CVE-2015-6071, CVE-2015-6074, and CVE-2015-6087.
nvd
CVE-2015-1736P3CRITICALCVSS 9.3v10v112015-06-10
CVE-2015-1736 [CRITICAL] CVE-2015-1736: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1737, and CVE-2015-1755.
nvd
CVE-2010-3331P3CRITICALCVSS 9.3v6v7+1 more2010-10-13
CVE-2010-3331 [CRITICAL] CWE-94 CVE-2010-3331: Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circum
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Mem
nvd
CVE-2014-0283P3CRITICALCVSS 9.3v92014-02-12
CVE-2014-0283 [CRITICAL] CWE-119 CVE-2014-0283: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-6045P3CRITICALCVSS 9.3v112015-11-13
CVE-2015-6045 [CRITICAL] CVE-2015-6045: Use-after-free vulnerability in the CElement object implementation in Microsoft Internet Explorer 11
Use-after-free vulnerability in the CElement object implementation in Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript that improperly interacts with use of the Cascading Style Sheets (CSS) empty-cells property for a TABLE element, aka "Internet Explorer
nvd
CVE-2010-3326P3CRITICALCVSS 9.3v62010-10-13
CVE-2010-3326 [CRITICAL] CWE-94 CVE-2010-3326: Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attack
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2013-3915P3CRITICALCVSS 9.3v6v7+4 more2013-11-13
CVE-2013-3915 [CRITICAL] CWE-119 CVE-2013-3915: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3917.
nvd
CVE-2014-0277P3CRITICALCVSS 9.3v82014-02-12
CVE-2014-0277 [CRITICAL] CWE-119 CVE-2014-0277: Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and CVE-2014-0279.
nvd
CVE-2013-3912P3CRITICALCVSS 9.3v8v9+2 more2013-11-13
CVE-2013-3912 [CRITICAL] CWE-119 CVE-2013-3912: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3916.
nvd
CVE-2007-0945P3CRITICALCVSS 9.3v6v6.0+1 more2007-05-08
CVE-2007-0945 [CRITICAL] CVE-2007-0945: Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server
Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corruption, aka "Property Memory Corruption Vulnerability."
nvd
CVE-2011-2000P3CRITICALCVSS 9.3v6v7+2 more2011-10-12
CVE-2011-2000 [CRITICAL] CVE-2011-2000: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Body Element Remote Code Execution Vulnerability."
nvd
CVE-2015-6143P3CRITICALCVSS 9.3v112015-12-09
CVE-2015-6143 [CRITICAL] CVE-2015-6143: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142, CVE-2015-6153, CVE-2015-6158, CVE-2015-6159, and CVE-2015-6160.
nvd
CVE-2015-6160P3CRITICALCVSS 9.3v112015-12-09
CVE-2015-6160 [CRITICAL] CVE-2015-6160: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6158, and CVE-2015-6159.
nvd
CVE-2014-0284P3CRITICALCVSS 9.3v9v102014-02-12
CVE-2014-0284 [CRITICAL] CWE-119 CVE-2014-0284: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2002-0648P4MEDIUMCVSS 5.0PoCv5.01v5.5+1 more2002-09-24
CVE-2002-0648 [MEDIUM] CVE-2002-0648: The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0
The legacy data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.
nvd
CVE-2011-1256P3CRITICALCVSS 9.3v6v7+1 more2011-06-16
CVE-2011-1256 [CRITICAL] CWE-908 CVE-2011-1256: Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Modification Memory Corruption Vulnerability."
nvd
CVE-2010-0492P3HIGHCVSS 8.1v8v8.0.60012010-03-31
CVE-2010-0492 [HIGH] CWE-94 CVE-2010-0492: Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers
Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
nvd
CVE-2010-2560P3CRITICALCVSS 9.3v6v7+1 more2010-08-11
CVE-2010-2560 [CRITICAL] CWE-787 CVE-2010-2560: Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Layout Memory Corruption Vulnerability."
nvd
CVE-2008-2259P3CRITICALCVSS 9.3v6v72008-08-13
CVE-2008-2259 [CRITICAL] CWE-20 CVE-2008-2259: Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print previ
Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors, aka "HTML Component Handling Vulnerability."
nvd