cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 44 of 80
CVE-2018-0991P3HIGHCVSS 7.5v10v112018-04-12
CVE-2018-0991 [HIGH] CVE-2018-0991: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0870, CVE-2018-0997, CVE-2018-1018, CVE-2018-1020.
nvd
CVE-2008-2258P3CRITICALCVSS 9.3v5.01v6+1 more2008-08-13
CVE-2008-2258 [CRITICAL] CVE-2008-2258: Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, whic Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order" with "particular functions ... performed on" document objects, aka "HTML Objects Memory Corruptio
nvd
CVE-2001-0875P4HIGHCVSS 7.5PoCv5.5v6.02001-11-26
CVE-2001-0875 [HIGH] CVE-2001-0875: Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to mis Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.
nvd
CVE-2014-6348P3CRITICALCVSS 9.3v92014-11-11
CVE-2014-6348 [CRITICAL] CVE-2014-6348: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6342.
nvd
CVE-2015-0025P3CRITICALCVSS 9.3v102015-02-11
CVE-2015-0025 [CRITICAL] CVE-2015-0025: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0023.
nvd
CVE-2014-6342P3CRITICALCVSS 9.3v92014-11-11
CVE-2014-6342 [CRITICAL] CWE-399 CVE-2014-6342: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6348.
nvd
CVE-2010-0555P3CRITICALCVSS 9.3v6v7+1 more2010-02-04
CVE-2010-0555 [CRITICAL] CVE-2010-0555: Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML loca Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka t
nvd
CVE-2012-1858P4MEDIUMCVSS 4.3PoCv8v92012-06-12
CVE-2012-1858 [MEDIUM] CWE-200 CVE-2012-1858: The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicat The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability.
nvd
CVE-2006-1303P3CRITICALCVSS 9.3v5.0.1v6.02006-06-13
CVE-2006-1303 [CRITICAL] CWE-94 CVE-2006-1303: Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier a Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImag
nvd
CVE-2013-4015P4MEDIUMCVSS 6.9PoCv6v7+3 more2013-07-26
CVE-2013-4015 [MEDIUM] CWE-264 CVE-2013-4015: Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.
nvd
CVE-2008-3473P3CRITICALCVSS 9.3v5.01v6+1 more2008-10-15
CVE-2008-3473 [CRITICAL] CWE-264 CVE-2008-3473: Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origi Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."
nvd
CVE-2017-0238P3HIGHCVSS 7.5v9v10+1 more2017-05-12
CVE-2017-0238 [HIGH] CVE-2017-0238: A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting e A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and CVE-2017-0236.
nvd
CVE-2018-0762P3HIGHCVSS 7.5v10v11+1 more2018-01-04
CVE-2018-0762 [HIGH] CVE-2018-0762: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine han
nvd
CVE-2018-0772P3HIGHCVSS 7.5v10v9+1 more2018-01-04
CVE-2018-0772 [HIGH] CVE-2018-0772: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine han
nvd
CVE-2015-6145P3CRITICALCVSS 9.3v7v82015-12-09
CVE-2015-6145 [CRITICAL] CWE-119 CVE-2015-6145: Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a den Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6146.
nvd
CVE-2015-6146P3CRITICALCVSS 9.3v7v82015-12-09
CVE-2015-6146 [CRITICAL] CVE-2015-6146: Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a den Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6145.
nvd
CVE-2014-8966P3CRITICALCVSS 9.3v6v7+1 more2014-12-11
CVE-2014-8966 [CRITICAL] CWE-20 CVE-2014-8966: Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-6375P3CRITICALCVSS 9.3v82014-12-11
CVE-2014-6375 [CRITICAL] CWE-20 CVE-2014-6375: Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-6087P3CRITICALCVSS 9.3v7v8+3 more2015-11-11
CVE-2015-6087 [CRITICAL] CVE-2015-6087: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6066, CVE-2015-6070, CVE-2015-6071, CVE-2015-6074, and CVE-2015-6076.
nvd
CVE-2015-6066P3CRITICALCVSS 9.3v7v8+3 more2015-11-11
CVE-2015-6066 [CRITICAL] CWE-119 CVE-2015-6066: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6070, CVE-2015-6071, CVE-2015-6074, CVE-2015-6076, and CVE-2015-6087.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase