Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 40 of 80
CVE-2013-3125P3CRITICALCVSS 9.3v102013-06-12
CVE-2013-3125 [CRITICAL] CVE-2013-3125: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3120.
nvd
CVE-2013-3118P3CRITICALCVSS 9.3v102013-06-12
CVE-2013-3118 [CRITICAL] CWE-119 CVE-2013-3118: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3120 and CVE-2013-3125.
nvd
CVE-2013-3122P3CRITICALCVSS 9.3v92013-06-12
CVE-2013-3122 [CRITICAL] CVE-2013-3122: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3124.
nvd
CVE-2013-3124P3CRITICALCVSS 9.3v92013-06-12
CVE-2013-3124 [CRITICAL] CVE-2013-3124: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3122.
nvd
CVE-2016-0071P3HIGHCVSS 8.8v92016-02-10
CVE-2016-0071 [HIGH] CWE-119 CVE-2016-0071: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-0067P3HIGHCVSS 8.8v9v10+1 more2016-02-10
CVE-2016-0067 [HIGH] CVE-2016-0067: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0063, and CVE-2016-0072.
nvd
CVE-2013-3117P3CRITICALCVSS 9.3v92013-06-12
CVE-2013-3117 [CRITICAL] CWE-119 CVE-2013-3117: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3122 and CVE-2013-3124.
nvd
CVE-2007-0218P3CRITICALCVSS 9.3v5.01v6+1 more2007-06-12
CVE-2007-0218 [CRITICAL] CWE-94 CVE-2007-0218: Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instanti
Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.
nvd
CVE-2014-6327P3CRITICALCVSS 9.3v112014-12-11
CVE-2014-6327 [CRITICAL] CWE-20 CVE-2014-6327: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6329 and CVE-2014-6376.
nvd
CVE-2014-6376P3CRITICALCVSS 9.3v112014-12-11
CVE-2014-6376 [CRITICAL] CVE-2014-6376: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6327 and CVE-2014-6329.
nvd
CVE-2010-0246P3CRITICALCVSS 9.3v8v8.0.60012010-01-22
CVE-2010-0246 [CRITICAL] CVE-2010-0246: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and C
nvd
CVE-2010-0245P3CRITICALCVSS 9.3v8v8.0.60012010-01-22
CVE-2010-0245 [CRITICAL] CVE-2010-0245: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and C
nvd
CVE-2010-1261P3CRITICALCVSS 9.3v82010-06-08
CVE-2010-1261 [CRITICAL] CWE-94 CVE-2010-1261: The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted re
The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2016-3375P3HIGHCVSS 7.5v9v10+1 more2016-09-14
CVE-2016-3375 [HIGH] CWE-119 CVE-2016-3375: The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through
The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through 11, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow remote attackers to execute arbitrary code or cause a denial of service (memor
nvd
CVE-2010-0247P3CRITICALCVSS 9.3v6v6.0+16 more2010-01-22
CVE-2010-0247 [CRITICAL] CWE-94 CVE-2010-0247: Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 does not properly handle objects in memory, which
Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-1999-1575P4MEDIUMCVSS 5.1PoCv4.0.1v5.01999-09-10
CVE-1999-1575 [MEDIUM] CVE-1999-1575: The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (img
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe fo
nvd
CVE-2006-5581P3CRITICALCVSS 9.3≤ 62006-12-12
CVE-2006-5581 [CRITICAL] CVE-2006-5581: Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitr
Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via certain DHTML script functions, such as normalize, and "incorrectly created elements" that trigger memory corruption, aka "DHTML Script Function Memory Corruption Vulnerability."
nvd
CVE-2008-0078P3CRITICALCVSS 9.3v6v72008-02-12
CVE-2008-0078 [CRITICAL] CWE-94 CVE-2008-0078: Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6
Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."
nvd
CVE-2007-3041P3CRITICALCVSS 9.3v5.01v6+1 more2007-08-14
CVE-2007-3041 [CRITICAL] CVE-2007-3041: Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and
Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and 7 allows remote attackers to execute arbitrary code via unknown vectors related to Microsoft Visual Basic 6 objects and memory corruption, aka "ActiveX Object Memory Corruption Vulnerability."
nvd
CVE-2009-2530P3CRITICALCVSS 9.3v5.01v6+2 more2009-10-14
CVE-2009-2530 [CRITICAL] CWE-94 CVE-2009-2530: Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which all
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-25
nvd