Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
40
actively exploited
Public exploits
364
Exploited in wild
48
Severity breakdown
CRITICAL690HIGH450MEDIUM404LOW50

Vulnerabilities

Page 40 of 80
CVE-2014-1803CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-1803 [CRITICAL] CVE-2014-1803: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-2757.
nvd
CVE-2014-1779CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-1779 [CRITICAL] CVE-2014-1779: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.
nvd
CVE-2014-2775CRITICALCVSS 9.3PoCv9v10+1 more2014-06-11
CVE-2014-2775 [CRITICAL] CVE-2014-2775: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE
nvd
CVE-2014-1802CRITICALCVSS 9.3PoCv10v112014-06-11
CVE-2014-1802 [CRITICAL] CVE-2014-1802: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2
nvd
CVE-2014-1769CRITICALCVSS 9.3PoCv112014-06-11
CVE-2014-1769 [CRITICAL] CWE-94 CVE-2014-1769: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and C
nvd
CVE-2014-1795CRITICALCVSS 9.3PoCv9v10+1 more2014-06-11
CVE-2014-1795 [CRITICAL] CVE-2014-1795: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE
nvd
CVE-2014-2777HIGHCVSS 7.5PoCv8v9+2 more2014-06-11
CVE-2014-2777 [HIGH] CVE-2014-2777: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script wit Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-1778.
nvd
CVE-2014-1778MEDIUMCVSS 6.8PoCv8v9+2 more2014-06-11
CVE-2014-1778 [MEDIUM] CWE-264 CVE-2014-1778: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script wit Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.
nvd
CVE-2014-1777MEDIUMCVSS 4.3PoCv10v112014-06-11
CVE-2014-1777 [MEDIUM] CWE-200 CVE-2014-1777: Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2014-1771MEDIUMCVSS 6.8PoCv6v7+4 more2014-06-11
CVE-2014-1771 [MEDIUM] CWE-310 CVE-2014-1771: SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certifica SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerabil
nvd
CVE-2014-1770CRITICALCVSS 9.3PoCv6v7+4 more2014-05-22
CVE-2014-1770 [CRITICAL] CWE-399 CVE-2014-1770: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.
nvd
CVE-2014-1815CRITICALCVSS 9.3ExploitedPoCv6v7+4 more2014-05-14
CVE-2014-1815 [CRITICAL] CVE-2014-1815: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0310.
nvd
CVE-2014-0310CRITICALCVSS 9.3v6v7+4 more2014-05-14
CVE-2014-0310 [CRITICAL] CWE-119 CVE-2014-0310: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1815.
nvd
CVE-2014-1764CRITICALCVSS 10.0PoCv7v8+3 more2014-04-27
CVE-2014-1764 [CRITICAL] CWE-264 CVE-2014-1764: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypas Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2014-1766CRITICALCVSS 9.3PoCv9v10+1 more2014-04-27
CVE-2014-1766 [CRITICAL] CWE-119 CVE-2014-1766: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet
nvd
CVE-2014-1763CRITICALCVSS 10.0v9v10+1 more2014-04-27
CVE-2014-1763 [CRITICAL] CWE-399 CVE-2014-1763: Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2014-1776CRITICALCVSS 9.8KEVv6v7+4 more2014-04-27
CVE-2014-1776 [CRITICAL] CWE-416 CVE-2014-1776: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clari
nvd
CVE-2014-1762HIGHCVSS 7.5PoCv6v7+4 more2014-04-27
CVE-2014-1762 [HIGH] CVE-2014-1762: Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to exe Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun competition at CanSecWest 2014.
nvd
CVE-2014-1765HIGHCVSS 7.6v6v7+4 more2014-04-27
CVE-2014-1765 [HIGH] CWE-399 CVE-2014-1765: Multiple use-after-free vulnerabilities in Microsoft Internet Explorer 6 through 11 allow remote att Multiple use-after-free vulnerabilities in Microsoft Internet Explorer 6 through 11 allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2014-1753CRITICALCVSS 9.3v6v7+2 more2014-04-08
CVE-2014-1753 [CRITICAL] CWE-119 CVE-2014-1753: Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd