Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
40
actively exploited
Public exploits
364
Exploited in wild
48
Severity breakdown
CRITICAL690HIGH450MEDIUM404LOW50
Vulnerabilities
Page 43 of 80
CVE-2014-0280CRITICALCVSS 9.3v6v7+1 more2014-02-12
CVE-2014-0280 [CRITICAL] CWE-119 CVE-2014-0280: Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-0277CRITICALCVSS 9.3v82014-02-12
CVE-2014-0277 [CRITICAL] CWE-119 CVE-2014-0277: Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and CVE-2014-0279.
nvd
CVE-2014-0274CRITICALCVSS 9.3v9v10+1 more2014-02-12
CVE-2014-0274 [CRITICAL] CVE-2014-0274: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0288.
nvd
CVE-2014-0269CRITICALCVSS 9.3v6v7+3 more2014-02-12
CVE-2014-0269 [CRITICAL] CWE-119 CVE-2014-0269: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-0286CRITICALCVSS 9.3v6v7+4 more2014-02-12
CVE-2014-0286 [CRITICAL] CVE-2014-0286: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0285.
nvd
CVE-2014-0268MEDIUMCVSS 4.3v8v9+2 more2014-02-12
CVE-2014-0268 [MEDIUM] CWE-264 CVE-2014-0268: Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-k
Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-key creation, which allows remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2014-0293MEDIUMCVSS 4.3v9v10+1 more2014-02-12
CVE-2014-0293 [MEDIUM] CWE-200 CVE-2014-0293: Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1
Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
nvd
CVE-2013-3846CRITICALCVSS 9.3PoCv9v102013-12-29
CVE-2013-3846 [CRITICAL] CVE-2013-3846: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to exec
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CSpliceTreeEngine::InsertSplice object in an HTML document, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143 and CVE-2013-31
nvd
CVE-2013-3140CRITICALCVSS 9.3v92013-12-16
CVE-2013-3140 [CRITICAL] CWE-399 CVE-2013-3140: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted CMarkup object, aka "Internet Explorer Use After Free Vulnerability."
nvd
CVE-2013-5052CRITICALCVSS 9.3v72013-12-11
CVE-2013-5052 [CRITICAL] CWE-119 CVE-2013-5052: Microsoft Internet Explorer 7 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-5047CRITICALCVSS 9.3v6v7+4 more2013-12-11
CVE-2013-5047 [CRITICAL] CWE-119 CVE-2013-5047: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5048.
nvd
CVE-2013-5048CRITICALCVSS 9.3v6v7+4 more2013-12-11
CVE-2013-5048 [CRITICAL] CVE-2013-5048: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5047.
nvd
CVE-2013-5051CRITICALCVSS 9.3v10v112013-12-11
CVE-2013-5051 [CRITICAL] CWE-119 CVE-2013-5051: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-5049CRITICALCVSS 9.3v6v7+2 more2013-12-11
CVE-2013-5049 [CRITICAL] CWE-119 CVE-2013-5049: Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-5045MEDIUMCVSS 6.2PoCv10v112013-12-11
CVE-2013-5045 [MEDIUM] CWE-20 CVE-2013-5045: Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mec
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2013-5046MEDIUMCVSS 6.2v7v8+3 more2013-12-11
CVE-2013-5046 [MEDIUM] CWE-20 CVE-2013-5046: Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection
Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2013-3915CRITICALCVSS 9.3v6v7+4 more2013-11-13
CVE-2013-3915 [CRITICAL] CWE-119 CVE-2013-3915: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3917.
nvd
CVE-2013-3917CRITICALCVSS 9.3v6v7+4 more2013-11-13
CVE-2013-3917 [CRITICAL] CVE-2013-3917: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3915.
nvd
CVE-2013-3916CRITICALCVSS 9.3v8v9+2 more2013-11-13
CVE-2013-3916 [CRITICAL] CVE-2013-3916: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3912.
nvd
CVE-2013-3910CRITICALCVSS 9.3v6v7+2 more2013-11-13
CVE-2013-3910 [CRITICAL] CWE-119 CVE-2013-3910: Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd