Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 43 of 80
CVE-2015-2401P3CRITICALCVSS 9.3v9v10+1 more2015-07-14
CVE-2015-2401 [CRITICAL] CVE-2015-2401: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2408.
nvd
CVE-2015-2383P3CRITICALCVSS 9.3v112015-07-14
CVE-2015-2383 [CRITICAL] CWE-119 CVE-2015-2383: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2384 and CVE-2015-2425.
nvd
CVE-2015-2384P3CRITICALCVSS 9.3v112015-07-14
CVE-2015-2384 [CRITICAL] CVE-2015-2384: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2425.
nvd
CVE-2015-1667P3CRITICALCVSS 9.3v8v9+2 more2015-04-14
CVE-2015-1667 [CRITICAL] CWE-399 CVE-2015-1667: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-1666P3CRITICALCVSS 9.3v6v7+4 more2015-04-14
CVE-2015-1666 [CRITICAL] CVE-2015-1666: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1652.
nvd
CVE-2015-1657P3CRITICALCVSS 9.3v9v10+1 more2015-04-14
CVE-2015-1657 [CRITICAL] CWE-399 CVE-2015-1657: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-1662P3CRITICALCVSS 9.3v112015-04-14
CVE-2015-1662 [CRITICAL] CVE-2015-1662: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1659 and CVE-2015-1665.
nvd
CVE-2007-1750P3CRITICALCVSS 9.3v5.01v6+1 more2007-06-12
CVE-2007-1750 [CRITICAL] CVE-2007-1750: Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitr
Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.
nvd
CVE-2001-0664P4HIGHCVSS 7.5PoCv5.01v5.52001-10-30
CVE-2001-0664 [HIGH] CVE-2001-0664: Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."
nvd
CVE-2014-6374P3CRITICALCVSS 9.3v6v7+4 more2014-12-11
CVE-2014-6374 [CRITICAL] CWE-119 CVE-2014-6374: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-7195P3HIGHCVSS 7.5v9v10+1 more2016-11-10
CVE-2016-7195 [HIGH] CWE-119 CVE-2016-7195: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7198.
nvd
CVE-2016-0112P3HIGHCVSS 7.5v9v10+1 more2016-03-09
CVE-2016-0112 [HIGH] CVE-2016-0112: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0113.
nvd
CVE-2016-0113P3HIGHCVSS 7.5v9v10+1 more2016-03-09
CVE-2016-0113 [HIGH] CVE-2016-0113: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0112.
nvd
CVE-2016-0107P3HIGHCVSS 7.5v9v10+1 more2016-03-09
CVE-2016-0107 [HIGH] CVE-2016-0107: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113.
nvd
CVE-2016-0106P3HIGHCVSS 7.5v112016-03-09
CVE-2016-0106 [HIGH] CVE-2016-0106: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114.
nvd
CVE-2016-0114P3HIGHCVSS 7.5v112016-03-09
CVE-2016-0114 [HIGH] CVE-2016-0114: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, and CVE-2016-0109.
nvd
CVE-2016-3290P3HIGHCVSS 7.5v112016-08-09
CVE-2016-3290 [HIGH] CVE-2016-3290: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web p
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3288.
nvd
CVE-2018-8287P3HIGHCVSS 7.5v11v102018-07-11
CVE-2018-8287 [HIGH] CVE-2018-8287: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8288, CVE-2018-8291, CVE-2018-
nvd
CVE-2018-1020P3HIGHCVSS 7.5v10v11+1 more2018-04-12
CVE-2018-1020 [HIGH] CVE-2018-1020: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0870, CVE-2018-0991, CVE-2018-0997, CVE-2018-1018.
nvd
CVE-2008-2257P3CRITICALCVSS 9.3v5.01v6+1 more2008-08-13
CVE-2008-2257 [CRITICAL] CWE-399 CVE-2008-2257: Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, whic
Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption
nvd