cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 48 of 80
CVE-2015-6082P3CRITICALCVSS 9.3v112015-11-11
CVE-2015-6082 [CRITICAL] CVE-2015-6082: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072, CVE-2015-6073, CVE-2015-6075, CVE-2015-6077, CVE-2015-6079, and CVE-2015-6080.
nvd
CVE-2015-6079P3CRITICALCVSS 9.3v112015-11-11
CVE-2015-6079 [CRITICAL] CVE-2015-6079: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072, CVE-2015-6073, CVE-2015-6075, CVE-2015-6077, CVE-2015-6080, and CVE-2015-6082.
nvd
CVE-2015-6072P3CRITICALCVSS 9.3v112015-11-11
CVE-2015-6072 [CRITICAL] CVE-2015-6072: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6073, CVE-2015-6075, CVE-2015-6077, CVE-2015-6079, CVE-2015-6080, and CVE-2015-6082.
nvd
CVE-2015-1732P3CRITICALCVSS 9.3v112015-06-10
CVE-2015-1732 [CRITICAL] CWE-399 CVE-2015-1732: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1742, CVE-2015-1747, CVE-2015-1750, and CVE-2015-1753.
nvd
CVE-2014-0321P3CRITICALCVSS 9.3v10v112014-03-12
CVE-2014-0321 [CRITICAL] CVE-2014-0321: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0313.
nvd
CVE-2015-6050P3CRITICALCVSS 9.3v102015-10-14
CVE-2015-6050 [CRITICAL] CWE-119 CVE-2015-6050: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-0102P3HIGHCVSS 7.5v112016-03-09
CVE-2016-0102 [HIGH] CWE-119 CVE-2016-0102: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114.
nvd
CVE-2016-0109P3HIGHCVSS 7.5v112016-03-09
CVE-2016-0109 [HIGH] CVE-2016-0109: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, and CVE-2016-0114.
nvd
CVE-2006-5162P4MEDIUMCVSS 5.0PoCv5.0v5.0.1+2 more2006-10-05
CVE-2006-5162 [MEDIUM] CVE-2006-5162: wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a de wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.
nvd
CVE-2009-2433P4MEDIUMCVSS 4.3PoCv7v7.0+6 more2009-07-10
CVE-2009-2433 [MEDIUM] CWE-119 CVE-2009-2433: Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote a Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
nvd
CVE-2014-1765P3HIGHCVSS 7.6v6v7+4 more2014-04-27
CVE-2014-1765 [HIGH] CWE-399 CVE-2014-1765: Multiple use-after-free vulnerabilities in Microsoft Internet Explorer 6 through 11 allow remote att Multiple use-after-free vulnerabilities in Microsoft Internet Explorer 6 through 11 allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2015-6184P3HIGHCVSS 8.1v7v8+3 more2016-03-09
CVE-2015-6184 [HIGH] CVE-2015-6184: The CAttrArray object implementation in Microsoft Internet Explorer 7 through 11 allows remote attac The CAttrArray object implementation in Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and memory corruption) via a malformed Cascading Style Sheets (CSS) token sequence in conjunction with modifications to HTML elements, aka "Internet Explorer Memory Corruption Vulnerabili
nvd
CVE-2017-8524P3HIGHCVSS 7.5v112017-06-15
CVE-2017-8524 [HIGH] CVE-2017-8524: Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows R Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in
nvd
CVE-2016-7279P3HIGHCVSS 7.5v9v10+1 more2016-12-20
CVE-2016-7279 [HIGH] CWE-119 CVE-2016-7279: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2017-8653P3HIGHCVSS 7.5v9v10+1 more2017-08-08
CVE-2017-8653 [HIGH] CWE-119 CVE-2017-8653: Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and W Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to Microsoft browsers improperly accessing objects in memory, aka "Mic
nvd
CVE-2018-0954P3HIGHCVSS 7.5v9v10+1 more2018-05-09
CVE-2018-0954 [HIGH] CVE-2018-0954: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE
nvd
CVE-2018-1022P3HIGHCVSS 7.5v112018-05-09
CVE-2018-1022 [HIGH] CVE-2018-1022: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, C
nvd
CVE-2018-1001P3HIGHCVSS 7.5v10v11+1 more2018-04-12
CVE-2018-1001 [HIGH] CVE-2018-1001: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0988, CVE-2018-0996.
nvd
CVE-2018-0996P3HIGHCVSS 7.5v10v11+1 more2018-04-12
CVE-2018-0996 [HIGH] CVE-2018-0996: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0988, CVE-2018-1001.
nvd
CVE-2017-11886P3HIGHCVSS 7.5v11v10+1 more2017-12-12
CVE-2017-11886 [HIGH] CWE-119 CVE-2017-11886: Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Ser Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corrup
nvd
Microsoft Internet Explorer vulnerabilities | cvebase