Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 47 of 80
CVE-2018-8178P3HIGHCVSS 7.5v112018-05-09
CVE-2018-8178 [HIGH] CWE-787 CVE-2018-8178: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in me
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.
nvd
CVE-2006-2378P3MEDIUMCVSS 6.8v5.0.1v6.02006-06-13
CVE-2006-2378 [MEDIUM] CVE-2006-2378: Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and S
Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
nvd
CVE-2009-2529P3HIGHCVSS 8.1v5.01v6+2 more2009-10-14
CVE-2009-2529 [HIGH] CWE-94 CVE-2009-2529: Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validatio
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability."
nvd
CVE-2020-1570P3HIGHCVSS 7.5v11v92020-08-17
CVE-2020-1570 [HIGH] CWE-787 CVE-2020-1570: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights a
nvd
CVE-2016-3293P3HIGHCVSS 7.5v9v10+1 more2016-08-09
CVE-2016-3293 [HIGH] CWE-119 CVE-2016-3293: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to execute arbitrary code v
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2018-8371P3HIGHCVSS 7.5v11v10+1 more2018-08-15
CVE-2018-8371 [HIGH] CVE-2018-8371: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8372, CVE-2018-837
nvd
CVE-2008-4787P4MEDIUMCVSS 5.8PoCv62008-10-29
CVE-2008-4787 [MEDIUM] CVE-2008-4787: Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof th
Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ticket MSRC7899, a related issue to CVE-2003-1025.
nvd
CVE-2007-3670P4MEDIUMCVSS 4.3PoCv6v7.02007-07-10
CVE-2007-3670 [MEDIUM] CWE-79 CVE-2007-3670: Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefo
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that
nvd
CVE-2018-8570P3HIGHCVSS 7.5v112018-11-14
CVE-2018-8570 [HIGH] CWE-787 CVE-2018-8570: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11.
nvd
CVE-2017-0201P3HIGHCVSS 7.5v9v102017-04-12
CVE-2017-0201 [HIGH] CVE-2017-0201: A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VB
A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VBScript engines render when handling objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is un
nvd
CVE-2010-3886P4MEDIUMCVSS 4.3PoCv82010-10-08
CVE-2010-3886 [MEDIUM] CWE-200 CVE-2010-3886: The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the
nvd
CVE-2016-3353P3HIGHCVSS 8.3v9v10+1 more2016-09-14
CVE-2016-3353 [HIGH] CWE-254 CVE-2016-3353: Microsoft Internet Explorer 9 through 11 mishandles .url files from the Internet zone, which allows
Microsoft Internet Explorer 9 through 11 mishandles .url files from the Internet zone, which allows remote attackers to bypass intended access restrictions via a crafted file, aka "Internet Explorer Security Feature Bypass."
nvd
CVE-2006-7066P4HIGHCVSS 7.1PoCv6.02007-03-02
CVE-2006-7066 [HIGH] CVE-2006-7066: Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame, which triggers a NULL pointer dereference. NOTE: it was later reported that 7.0.6000
nvd
CVE-2013-3166P4MEDIUMCVSS 4.3PoCv6v7+3 more2013-07-10
CVE-2013-3166 [MEDIUM] CVE-2013-3166: Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote a
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via vectors involving incorrect auto-selection of the Shift JIS encoding, leading to cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability," a different vulnerability than CVE-2013-0015.
nvd
CVE-2006-2218P3CRITICALCVSS 9.3v6.02006-05-05
CVE-2006-2218 [CRITICAL] CVE-2006-2218: Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attacke
Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.
nvd
CVE-2020-1064P3HIGHCVSS 7.5v9v112020-05-21
CVE-2020-1064 [HIGH] CVE-2020-1064: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.
nvd
CVE-2008-3472P3CRITICALCVSS 9.3v5.01v6+1 more2008-10-15
CVE-2008-3472 [CRITICAL] CWE-264 CVE-2008-3472: Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origi
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability."
nvd
CVE-2019-1208P3HIGHCVSS 7.5v9v10+1 more2019-09-11
CVE-2019-1208 [HIGH] CWE-416 CVE-2019-1208: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1236.
nvd
CVE-2014-6373P3CRITICALCVSS 9.3v102014-12-11
CVE-2014-6373 [CRITICAL] CWE-20 CVE-2014-6373: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-6080P3CRITICALCVSS 9.3v112015-11-11
CVE-2015-6080 [CRITICAL] CVE-2015-6080: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072, CVE-2015-6073, CVE-2015-6075, CVE-2015-6077, CVE-2015-6079, and CVE-2015-6082.
nvd