Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 29 of 80
CVE-2015-2493P3CRITICALCVSS 9.3v82015-09-09
CVE-2015-2493 [CRITICAL] CWE-119 CVE-2015-2493: The (1) VBScript and (2) JScript engines in Microsoft Internet Explorer 8 allow remote attackers to
The (1) VBScript and (2) JScript engines in Microsoft Internet Explorer 8 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2011-1251P3CRITICALCVSS 9.3v82011-06-16
CVE-2011-1251 [CRITICAL] CWE-908 CVE-2011-1251: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Manipulation Memory Corruption Vulnerability."
nvd
CVE-2011-1266P3CRITICALCVSS 9.3v6v7+1 more2011-06-16
CVE-2011-1266 [CRITICAL] CWE-908 CVE-2011-1266: The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through
The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "VML Memory Corruption Vulnerability."
nvd
CVE-2013-3203P3CRITICALCVSS 9.3v9v102013-09-11
CVE-2013-3203 [CRITICAL] CVE-2013-3203: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.
nvd
CVE-2011-1993P3CRITICALCVSS 9.3v6v7+2 more2011-10-12
CVE-2011-1993 [CRITICAL] CVE-2011-1993: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Scroll Event Remote Code Execution Vulnerability."
nvd
CVE-2007-3902P3CRITICALCVSS 9.3v5v5.01+13 more2007-12-12
CVE-2007-3902 [CRITICAL] CWE-189 CVE-2007-3902: Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Exp
Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2011-1964P3CRITICALCVSS 9.3v6v7+2 more2011-08-10
CVE-2011-1964 [CRITICAL] CWE-908 CVE-2011-1964: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Style Object Memory Corruption Vulnerability."
nvd
CVE-2010-0490P3CRITICALCVSS 9.3v7v6+2 more2010-03-31
CVE-2010-0490 [CRITICAL] CWE-94 CVE-2010-0490: Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which all
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2010-0491P3CRITICALCVSS 9.3v6v5.012010-03-31
CVE-2010-0491 [CRITICAL] CWE-399 CVE-2010-0491: Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote att
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."
nvd
CVE-2011-1262P3CRITICALCVSS 9.3v7v8+1 more2011-06-16
CVE-2011-1262 [CRITICAL] CWE-908 CVE-2011-1262: Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "HTTP Redirect Memory Corruption Vulnerability."
nvd
CVE-2014-0276P3CRITICALCVSS 9.3v8v92014-02-12
CVE-2014-0276 [CRITICAL] CWE-119 CVE-2014-0276: Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a den
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-6153P3CRITICALCVSS 9.3v112015-12-09
CVE-2015-6153 [CRITICAL] CWE-119 CVE-2015-6153: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142, CVE-2015-6143, CVE-2015-6158, CVE-2015-6159, and CVE-2015-616
nvd
CVE-2015-6154P3CRITICALCVSS 9.3v7v8+3 more2015-12-09
CVE-2015-6154 [CRITICAL] CVE-2015-6154: Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6150.
nvd
CVE-2015-6158P3CRITICALCVSS 9.3v112015-12-09
CVE-2015-6158 [CRITICAL] CVE-2015-6158: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6159, and CVE-2015-6160.
nvd
CVE-2015-6140P3CRITICALCVSS 9.3v112015-12-09
CVE-2015-6140 [CRITICAL] CWE-119 CVE-2015-6140: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6158, CVE-2015-6159, and CVE-2015-616
nvd
CVE-2015-1750P3CRITICALCVSS 9.3v112015-06-10
CVE-2015-1750 [CRITICAL] CVE-2015-1750: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1742, CVE-2015-1747, and CVE-2015-1753.
nvd
CVE-2014-4137P3CRITICALCVSS 9.3v6v72014-10-15
CVE-2014-4137 [CRITICAL] CVE-2014-4137: Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a den
Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4133.
nvd
CVE-2012-1879P3HIGHCVSS 8.1v7v8+2 more2012-06-12
CVE-2012-1879 [HIGH] CWE-94 CVE-2012-1879: Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access an undefined memory location, aka "insertAdjacentText Remote Code Execution Vulnerability."
nvd
CVE-2014-2796P3CRITICALCVSS 9.3v10v112014-08-12
CVE-2014-2796 [CRITICAL] CWE-119 CVE-2014-2796: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.
nvd
CVE-2014-4051P3CRITICALCVSS 9.3v8v9+2 more2014-08-12
CVE-2014-4051 [CRITICAL] CVE-2014-4051: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2784.
nvd