Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 46 of 80
CVE-2014-0306P3CRITICALCVSS 9.3v8v92014-03-12
CVE-2014-0306 [CRITICAL] CWE-119 CVE-2014-0306: Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a den
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-1760P3CRITICALCVSS 9.3v112014-04-08
CVE-2014-1760 [CRITICAL] CWE-119 CVE-2014-1760: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-5048P3CRITICALCVSS 9.3v6v7+4 more2013-12-11
CVE-2013-5048 [CRITICAL] CVE-2013-5048: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5047.
nvd
CVE-2013-5052P3CRITICALCVSS 9.3v72013-12-11
CVE-2013-5052 [CRITICAL] CWE-119 CVE-2013-5052: Microsoft Internet Explorer 7 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-5047P3CRITICALCVSS 9.3v6v7+4 more2013-12-11
CVE-2013-5047 [CRITICAL] CWE-119 CVE-2013-5047: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5048.
nvd
CVE-2013-5051P3CRITICALCVSS 9.3v10v112013-12-11
CVE-2013-5051 [CRITICAL] CWE-119 CVE-2013-5051: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2013-5049P3CRITICALCVSS 9.3v6v7+2 more2013-12-11
CVE-2013-5049 [CRITICAL] CWE-119 CVE-2013-5049: Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-3382P3HIGHCVSS 7.5v9v10+1 more2016-10-14
CVE-2016-3382 [HIGH] CWE-119 CVE-2016-3382: The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote at
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by the Chakra JavaScript engine, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2017-0228P3HIGHCVSS 7.5v112017-05-12
CVE-2017-0228 [HIGH] CVE-2017-0228: A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines ren
A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.
nvd
CVE-2016-0192P3HIGHCVSS 7.5v9v10+1 more2016-05-11
CVE-2016-0192 [HIGH] CWE-119 CVE-2016-0192: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2016-3390P3HIGHCVSS 7.5v112016-10-14
CVE-2016-3390 [HIGH] CWE-119 CVE-2016-3390: The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by the Chakra JavaScript engine, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2020-1403P3HIGHCVSS 7.5v11v92020-07-14
CVE-2020-1403 [HIGH] CVE-2020-1403: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
nvd
CVE-2006-2094P4MEDIUMCVSS 5.1PoCv5.0v5.0.1+3 more2006-04-29
CVE-2006-2094 [MEDIUM] CWE-362 CVE-2006-2094: Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1,
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into
nvd
CVE-2018-0889P3HIGHCVSS 7.5v9v10+1 more2018-03-14
CVE-2018-0889 [HIGH] CVE-2018-0889: Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote cod
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876, CVE-2018-0893, CVE-2018-0925, and CVE-2018-0935.
nvd
CVE-2018-8296P3HIGHCVSS 7.5v112018-07-11
CVE-2018-8296 [HIGH] CVE-2018-8296: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8298.
nvd
CVE-2016-3321P4LOWCVSS 2.5PoCv10v112016-08-09
CVE-2016-3321 [LOW] CWE-200 CVE-2016-3321: Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depend
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2018-1018P3HIGHCVSS 7.5v112018-04-12
CVE-2018-1018 [HIGH] CVE-2018-1018: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0870, CVE-2018-0991, CVE-2018-0997, CVE-2018-1020.
nvd
CVE-2018-0997P3HIGHCVSS 7.5v112018-04-12
CVE-2018-0997 [HIGH] CVE-2018-0997: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0870, CVE-2018-0991, CVE-2018-1018, CVE-2018-1020.
nvd
CVE-2018-0870P3HIGHCVSS 7.5v112018-04-12
CVE-2018-0870 [HIGH] CWE-787 CVE-2018-0870: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0991, CVE-2018-0997, CVE-2018-1018, CVE-2018-1020.
nvd
CVE-2018-0988P3HIGHCVSS 7.5v10v11+1 more2018-04-12
CVE-2018-0988 [HIGH] CWE-787 CVE-2018-0988: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0996, CVE-2018-1001.
nvd