Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 4 of 80
CVE-2003-1041P2HIGHCVSS 7.5ExploitedPoCv5v5.5+1 more2004-06-14
CVE-2003-1041 [HIGH] CVE-2003-1041: Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified d
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
nvd
CVE-2005-2087P2MEDIUMCVSS 5.0ExploitedPoCv5.1v5.01+3 more2005-07-05
CVE-2005-2087 [MEDIUM] CWE-399 CVE-2005-2087: Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180
Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JV
nvd
CVE-2005-1790P3LOWCVSS 2.6ExploitedPoCv6.0.2800.1106v6.0.2900.21802005-06-01
CVE-2005-1790 [LOW] CWE-399 CVE-2005-1790: Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remo
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."
nvd
CVE-2004-1043P2MEDIUMCVSS 5.0ExploitedPoCv6.02004-12-31
CVE-2004-1043 [MEDIUM] CVE-2004-1043: Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using t
Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, whic
nvd
CVE-2004-0841P2MEDIUMCVSS 5.0ExploitedPoCv5.0.1v5.5+1 more2004-12-23
CVE-2004-0841 [MEDIUM] CVE-2004-0841: Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events tha
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
nvd
CVE-2018-8389P1HIGHCVSS 7.5ExploitedRansomwarev11v10+1 more2018-08-15
CVE-2018-8389 [HIGH] CVE-2018-8389: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-837
nvd
CVE-2020-0640P1HIGHCVSS 7.5ExploitedRansomwarev10v11+1 more2020-01-14
CVE-2020-0640 [HIGH] CWE-787 CVE-2020-0640: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
nvd
CVE-2009-3126P2CRITICALCVSS 9.3Exploitedv62009-10-14
CVE-2009-3126 [CRITICAL] CWE-189 CVE-2009-3126: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP
nvd
CVE-2009-2501P2CRITICALCVSS 9.3Exploitedv62009-10-14
CVE-2009-2501 [CRITICAL] CWE-119 CVE-2009-2501: Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Off
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 200
nvd
CVE-2016-3210P2HIGHCVSS 8.8Exploitedv112016-06-16
CVE-2016-3210 [HIGH] CWE-119 CVE-2016-3210: The Microsoft (1) JScript and (2) VBScript engines, as used in Internet Explorer 11, allow remote at
The Microsoft (1) JScript and (2) VBScript engines, as used in Internet Explorer 11, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2011-1345P2CRITICALCVSS 9.3Exploitedv82011-03-10
CVE-2011-1345 [CRITICAL] CVE-2011-1345: Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows rem
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object
nvd
CVE-2014-0324P2CRITICALCVSS 9.3Exploitedv8v9+2 more2014-03-12
CVE-2014-0324 [CRITICAL] CVE-2014-0324: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0312.
nvd
CVE-2019-0606P2HIGHCVSS 7.5Exploitedv112019-03-05
CVE-2019-0606 [HIGH] CWE-787 CVE-2019-0606: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
nvd
CVE-2019-0666P2HIGHCVSS 7.5Exploitedv9v10+1 more2019-04-08
CVE-2019-0666 [HIGH] CVE-2019-0666: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0667, CVE-2019-0772.
nvd
CVE-2018-0955P2HIGHCVSS 7.5Exploitedv9v10+1 more2018-05-09
CVE-2018-0955 [HIGH] CVE-2018-0955: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-095
nvd
CVE-2004-0566P2HIGHCVSS 7.5Exploitedv5.0v5.0.1+1 more2004-07-27
CVE-2004-0566 [HIGH] CVE-2004-0566: Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code vi
Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.
nvd
CVE-2018-8267P2HIGHCVSS 7.5Exploitedv10v11+1 more2018-06-14
CVE-2018-8267 [HIGH] CVE-2018-8267: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8243.
nvd
CVE-2018-0978P2HIGHCVSS 7.5Exploitedv10v11+1 more2018-06-14
CVE-2018-0978 [HIGH] CWE-787 CVE-2018-0978: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8249.
nvd
CVE-2016-3212P2MEDIUMCVSS 6.1Exploitedv9v10+1 more2016-06-16
CVE-2016-3212 [MEDIUM] CWE-79 CVE-2016-3212: The XSS Filter in Microsoft Internet Explorer 9 through 11 does not properly identify JavaScript, wh
The XSS Filter in Microsoft Internet Explorer 9 through 11 does not properly identify JavaScript, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, aka "Internet Explorer XSS Filter Vulnerability."
nvd
CVE-2014-0311P2CRITICALCVSS 9.3Exploitedv6v7+4 more2014-03-12
CVE-2014-0311 [CRITICAL] CVE-2014-0311: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0299 and CVE-2014-0305.
nvd