Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 3 of 80
CVE-2016-0162P2MEDIUMCVSS 4.3KEVv9v10+1 more2016-04-12
CVE-2016-0162 [MEDIUM] CVE-2016-0162: Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files
Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2019-0676P2MEDIUMCVSS 6.5KEVv10v112019-03-05
CVE-2019-0676 [MEDIUM] CVE-2019-0676: An information disclosure vulnerability exists when Internet Explorer improperly handles objects in
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
nvd
CVE-2009-0075P2CRITICALCVSS 9.3ExploitedPoCv72009-02-10
CVE-2009-0075 [CRITICAL] CWE-399 CVE-2009-0075: Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted obj
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2008-4844P2CRITICALCVSS 9.3ExploitedPoCv5.01v6+1 more2008-12-11
CVE-2008-4844 [CRITICAL] CWE-399 CVE-2008-4844: Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by ne
nvd
CVE-2010-3971P2CRITICALCVSS 9.3ExploitedPoCv7v82010-12-22
CVE-2010-3971 [CRITICAL] CWE-399 CVE-2010-3971: Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet,
nvd
CVE-2006-3730P2HIGHCVSS 8.8ExploitedPoCv6.02006-07-21
CVE-2006-3730 [HIGH] CWE-94 CVE-2006-3730: Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
nvd
CVE-2012-1875P2CRITICALCVSS 9.3ExploitedPoCv82012-06-12
CVE-2012-1875 [CRITICAL] CWE-94 CVE-2012-1875: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."
nvd
CVE-2007-3896P2CRITICALCVSS 9.3ExploitedPoCv7.02007-10-11
CVE-2007-3896 [CRITICAL] CVE-2007-3896: The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with I
The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might
nvd
CVE-2006-4868P2CRITICALCVSS 9.3ExploitedPoCv6.0v5.0.12006-09-19
CVE-2006-4868 [CRITICAL] CWE-119 CVE-2006-4868: Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
nvd
CVE-2019-0667P2HIGHCVSS 7.5ExploitedPoCv9v10+1 more2019-04-08
CVE-2019-0667 [HIGH] CVE-2019-0667: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0772.
nvd
CVE-2004-1050P2CRITICALCVSS 10.0ExploitedPoCv6.02004-12-31
CVE-2004-1050 [CRITICAL] CVE-2004-1050: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
nvd
CVE-2007-1765P2CRITICALCVSS 9.3ExploitedPoC≤ 62007-03-30
CVE-2007-1765 [CRITICAL] CVE-2007-1765: Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to exe
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet
nvd
CVE-2004-0549P2CRITICALCVSS 10.0ExploitedPoCv5.01v5.5+1 more2004-08-06
CVE-2004-0549 [CRITICAL] CVE-2004-0549: The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in
The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations,
nvd
CVE-2011-1255P2CRITICALCVSS 9.3ExploitedPoCv6v7+1 more2011-06-16
CVE-2011-1255 [CRITICAL] CWE-908 CVE-2011-1255: The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Exp
The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Time Element Memory Corruption Vulnerability."
nvd
CVE-2014-1815P2CRITICALCVSS 9.3ExploitedPoCv6v7+4 more2014-05-14
CVE-2014-1815 [CRITICAL] CVE-2014-1815: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0310.
nvd
CVE-2004-0727P2HIGHCVSS 7.5ExploitedPoCv6.0.2800.11062004-07-27
CVE-2004-0727 [HIGH] CVE-2004-0727: Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including
Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redi
nvd
CVE-2015-0072P2MEDIUMCVSS 4.3ExploitedPoCv9v10+1 more2015-02-07
CVE-2015-0072 [MEDIUM] CWE-79 CVE-2015-0072: Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote a
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Univer
nvd
CVE-2007-0024P2CRITICALCVSS 9.3ExploitedPoCv5.01v7.02007-01-09
CVE-2007-0024 [CRITICAL] CVE-2007-0024: Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet
Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a
nvd
CVE-2005-0053P2HIGHCVSS 7.5ExploitedPoCv5.0.1v5.5+1 more2005-05-02
CVE-2005-0053 [HIGH] CVE-2005-0053: Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and dr
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
nvd
CVE-2006-1359P2CRITICALCVSS 9.3ExploitedPoCv6.02006-03-23
CVE-2006-1359 [CRITICAL] CWE-94 CVE-2006-1359: Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
nvd