Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 42 of 80
CVE-2015-0049P3CRITICALCVSS 9.3v8v102015-02-11
CVE-2015-0049 [CRITICAL] CWE-399 CVE-2015-0049: Microsoft Internet Explorer 8 and 10 allows remote attackers to execute arbitrary code or cause a de
Microsoft Internet Explorer 8 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-0039P3CRITICALCVSS 9.3v10v112015-02-11
CVE-2015-0039 [CRITICAL] CVE-2015-0039: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0052, and CVE-2015-0068.
nvd
CVE-2014-6353P3CRITICALCVSS 9.3v6v7+3 more2014-11-11
CVE-2014-6353 [CRITICAL] CWE-399 CVE-2014-6353: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-2785P3CRITICALCVSS 9.3v72014-07-08
CVE-2014-2785 [CRITICAL] CWE-119 CVE-2014-2785: Microsoft Internet Explorer 7 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2018-8316P3HIGHCVSS 7.5v11v102018-08-15
CVE-2018-8316 [HIGH] CWE-20 CVE-2018-8316: A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks
A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading executable libraries, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2010-2558P3CRITICALCVSS 9.3v6v7+1 more2010-08-11
CVE-2010-2558 [CRITICAL] CWE-362 CVE-2010-2558: Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitra
Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability."
nvd
CVE-2010-3325P4MEDIUMCVSS 4.3PoCv6v7+1 more2010-10-13
CVE-2010-3325 [MEDIUM] CWE-200 CVE-2010-3325: Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in C
Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a crafted web site, aka "CSS Special Character Information Disclosure Vulnerability."
nvd
CVE-2001-0149P4MEDIUMCVSS 5.0PoC≤ 5.52001-06-02
CVE-2001-0149 [MEDIUM] CVE-2001-0149: Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrar
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.
nvd
CVE-2012-0168P3HIGHCVSS 7.6v6v7+2 more2012-04-10
CVE-2012-0168 [HIGH] CWE-94 CVE-2012-0168: Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary c
Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document that is not properly handled during a "Print table of links" print operation, aka "Print Feature Remote Code Execution Vulnerability."
nvd
CVE-2014-0308P3CRITICALCVSS 9.3v8v9+2 more2014-03-12
CVE-2014-0308 [CRITICAL] CVE-2014-0308: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0312, and CVE-2014-0324.
nvd
CVE-2013-3126P3CRITICALCVSS 9.3v9v102013-06-12
CVE-2013-3126 [CRITICAL] CWE-119 CVE-2013-3126: Microsoft Internet Explorer 9 and 10, when script debugging is enabled, does not properly handle obj
Microsoft Internet Explorer 9 and 10, when script debugging is enabled, does not properly handle objects in memory during the processing of script, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Internet Explorer Script Debug Vulnerability."
nvd
CVE-2013-3123P3CRITICALCVSS 9.3v8v9+1 more2013-06-12
CVE-2013-3123 [CRITICAL] CVE-2013-3123: Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.
nvd
CVE-2013-3141P3CRITICALCVSS 9.3v8v92013-06-12
CVE-2013-3141 [CRITICAL] CVE-2013-3141: Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a den
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.
nvd
CVE-2013-3119P3CRITICALCVSS 9.3v9v102013-06-12
CVE-2013-3119 [CRITICAL] CVE-2013-3119: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3114.
nvd
CVE-2013-3110P3CRITICALCVSS 9.3v8v92013-06-12
CVE-2013-3110 [CRITICAL] CWE-119 CVE-2013-3110: Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a den
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.
nvd
CVE-2013-3114P3CRITICALCVSS 9.3v9v102013-06-12
CVE-2013-3114 [CRITICAL] CWE-119 CVE-2013-3114: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a de
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3119.
nvd
CVE-2015-6156P3CRITICALCVSS 9.3v9v10+1 more2015-12-09
CVE-2015-6156 [CRITICAL] CVE-2015-6156: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6148.
nvd
CVE-2016-0064P3HIGHCVSS 8.8v102016-02-10
CVE-2016-0064 [HIGH] CWE-119 CVE-2016-0064: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-3289P3HIGHCVSS 7.5v112016-08-09
CVE-2016-3289 [HIGH] CWE-119 CVE-2016-3289: Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a craft
Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3322.
nvd
CVE-2015-6069P3CRITICALCVSS 9.3v8v9+2 more2015-11-11
CVE-2015-6069 [CRITICAL] CWE-119 CVE-2015-6069: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6081.
nvd