cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 35 of 80
CVE-2019-1221P3HIGHCVSS 7.5v112019-09-11
CVE-2019-1221 [HIGH] CWE-787 CVE-2019-1221: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'.
nvd
CVE-2014-0302P3CRITICALCVSS 9.3v6v7+1 more2014-03-12
CVE-2014-0302 [CRITICAL] CWE-119 CVE-2014-0302: Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0303.
nvd
CVE-2014-0303P3CRITICALCVSS 9.3v6v7+1 more2014-03-12
CVE-2014-0303 [CRITICAL] CVE-2014-0303: Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0302.
nvd
CVE-2013-3885P3CRITICALCVSS 9.3v102013-10-09
CVE-2013-3885 [CRITICAL] CVE-2013-3885: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3872, CVE-2013-3873, and CVE-2013-3882.
nvd
CVE-2013-3873P3CRITICALCVSS 9.3v102013-10-09
CVE-2013-3873 [CRITICAL] CVE-2013-3873: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3872, CVE-2013-3882, and CVE-2013-3885.
nvd
CVE-2013-3882P3CRITICALCVSS 9.3v102013-10-09
CVE-2013-3882 [CRITICAL] CVE-2013-3882: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3872, CVE-2013-3873, and CVE-2013-3885.
nvd
CVE-2013-3886P3CRITICALCVSS 9.3v9v102013-10-09
CVE-2013-3886 [CRITICAL] CWE-119 CVE-2013-3886: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-3189P3CRITICALCVSS 9.3v8v92013-08-14
CVE-2013-3189 [CRITICAL] CVE-2013-3189: Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a den Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3188.
nvd
CVE-2017-8625P3HIGHCVSS 8.8v112017-08-08
CVE-2017-8625 [HIGH] CWE-276 CVE-2017-8625: Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker t Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka "Internet Explorer Security Feature Bypass Vulnerability".
nvd
CVE-2007-0947P3CRITICALCVSS 9.3v6v7.02007-05-08
CVE-2007-0947 [CRITICAL] CVE-2007-0947: Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issu
nvd
CVE-2008-1085P3CRITICALCVSS 9.3v6v72008-04-08
CVE-2008-1085 [CRITICAL] CWE-94 CVE-2008-1085: Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows re Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler.
nvd
CVE-2013-3142P3CRITICALCVSS 9.3v6v7+3 more2013-06-12
CVE-2013-3142 [CRITICAL] CVE-2013-3142: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3139.
nvd
CVE-2013-3191P3CRITICALCVSS 9.3v9v102013-08-14
CVE-2013-3191 [CRITICAL] CVE-2013-3191: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3187 and CVE-2013-3193.
nvd
CVE-2013-3190P3CRITICALCVSS 9.3v8v9+1 more2013-08-14
CVE-2013-3190 [CRITICAL] CWE-119 CVE-2013-3190: Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2018-8242P3HIGHCVSS 7.5v10v11+1 more2018-07-11
CVE-2018-8242 [HIGH] CWE-787 CVE-2018-8242: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-
nvd
CVE-2013-3121P3CRITICALCVSS 9.3v6v7+3 more2013-06-12
CVE-2013-3121 [CRITICAL] CVE-2013-3121: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3139, and CVE-2013-3142.
nvd
CVE-2009-3673P3CRITICALCVSS 9.3v5.0.1v6+2 more2009-12-09
CVE-2009-3673 [CRITICAL] CWE-94 CVE-2009-3673: Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2013-3208P3CRITICALCVSS 9.3v8v9+1 more2013-09-11
CVE-2013-3208 [CRITICAL] CWE-119 CVE-2013-3208: Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-3113P3CRITICALCVSS 9.3v6v7+3 more2013-06-12
CVE-2013-3113 [CRITICAL] CVE-2013-3113: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.
nvd
CVE-2013-3139P3CRITICALCVSS 9.3v6v7+3 more2013-06-12
CVE-2013-3139 [CRITICAL] CVE-2013-3139: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3142.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase