cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 34 of 80
CVE-2008-2259P3CRITICALCVSS 9.3v6v72008-08-13
CVE-2008-2259 [CRITICAL] CWE-20 CVE-2008-2259: Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print previ Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors, aka "HTML Component Handling Vulnerability."
nvd
CVE-2015-2448P3CRITICALCVSS 9.3v9v102015-08-14
CVE-2015-2448 [CRITICAL] CWE-119 CVE-2015-2448: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."
nvd
CVE-2011-1254P3CRITICALCVSS 9.3v6v7+1 more2011-06-16
CVE-2011-1254 [CRITICAL] CWE-908 CVE-2011-1254: Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows rem Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Drag and Drop Memory Corruption Vulnerability."
nvd
CVE-2011-1266P3CRITICALCVSS 9.3v6v7+1 more2011-06-16
CVE-2011-1266 [CRITICAL] CWE-908 CVE-2011-1266: The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "VML Memory Corruption Vulnerability."
nvd
CVE-2004-0420P3CRITICALCVSS 10.0v6.0v6.0.2800.11062004-07-07
CVE-2004-0420 [CRITICAL] CVE-2004-0420: The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, a The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.
nvd
CVE-2007-3902P3CRITICALCVSS 9.3v5v5.01+13 more2007-12-12
CVE-2007-3902 [CRITICAL] CWE-189 CVE-2007-3902: Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Exp Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2014-4084P3CRITICALCVSS 9.3v102014-09-10
CVE-2014-4084 [CRITICAL] CWE-119 CVE-2014-4084: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4093.
nvd
CVE-2014-0272P3CRITICALCVSS 9.3v8v9+1 more2014-02-12
CVE-2014-0272 [CRITICAL] CWE-119 CVE-2014-0272: Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-0269P3CRITICALCVSS 9.3v6v7+3 more2014-02-12
CVE-2014-0269 [CRITICAL] CWE-119 CVE-2014-0269: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-4128P3CRITICALCVSS 9.3v6v7+4 more2014-10-15
CVE-2014-4128 [CRITICAL] CWE-20 CVE-2014-4128: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-4134P3CRITICALCVSS 9.3v6v7+1 more2014-10-15
CVE-2014-4134 [CRITICAL] CWE-20 CVE-2014-4134: Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2008-0076P3CRITICALCVSS 9.3v6v72008-02-12
CVE-2008-0076 [CRITICAL] CWE-94 CVE-2008-0076: Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote at Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."
nvd
CVE-2014-0280P3CRITICALCVSS 9.3v6v7+1 more2014-02-12
CVE-2014-0280 [CRITICAL] CWE-119 CVE-2014-0280: Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-4058P3CRITICALCVSS 9.3v9v10+1 more2014-08-12
CVE-2014-4058 [CRITICAL] CWE-119 CVE-2014-4058: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-6155P3CRITICALCVSS 9.3v10v112015-12-09
CVE-2015-6155 [CRITICAL] CWE-119 CVE-2015-6155: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2015-6154P3CRITICALCVSS 9.3v7v8+3 more2015-12-09
CVE-2015-6154 [CRITICAL] CVE-2015-6154: Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitr Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6150.
nvd
CVE-2015-6078P3CRITICALCVSS 9.3v9v10+1 more2015-11-11
CVE-2015-6078 [CRITICAL] CVE-2015-6078: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6065.
nvd
CVE-2015-0043P3CRITICALCVSS 9.3v8v9+2 more2015-02-11
CVE-2015-0043 [CRITICAL] CWE-399 CVE-2015-0043: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2011-0346P3HIGHCVSS 8.1v6v7+1 more2011-01-07
CVE-2011-0346 [HIGH] CWE-399 CVE-2011-0346: Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Ex Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cros
nvd
CVE-2014-4099P3CRITICALCVSS 9.3v9v10+1 more2014-09-10
CVE-2014-4099 [CRITICAL] CWE-119 CVE-2014-4099: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase