Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
40
actively exploited
Public exploits
360
Exploited in wild
48
Severity breakdown
CRITICAL690HIGH450MEDIUM404LOW50
Vulnerabilities
Page 5 of 80
CVE-2019-0763HIGHCVSS 7.5v10v112019-04-09
CVE-2019-0763 [HIGH] CWE-787 CVE-2019-0763: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
nvd
CVE-2019-0752HIGHCVSS 7.5KEVPoCv11v102019-04-09
CVE-2019-0752 [HIGH] CVE-2019-0752: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.
nvd
CVE-2019-0862HIGHCVSS 7.5v11v102019-04-09
CVE-2019-0862 [HIGH] CVE-2019-0862: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0752, CVE-2019-0753.
nvd
CVE-2019-0764MEDIUMCVSS 6.5v10v11+1 more2019-04-09
CVE-2019-0764 [MEDIUM] CWE-88 CVE-2019-0764: A tampering vulnerability exists when Microsoft browsers do not properly validate input under specif
A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'.
nvd
CVE-2019-0746MEDIUMCVSS 6.5v10v11+1 more2019-04-09
CVE-2019-0746 [MEDIUM] CVE-2019-0746: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.
nvd
CVE-2019-0768MEDIUMCVSS 4.3PoCv112019-04-09
CVE-2019-0768 [MEDIUM] CVE-2019-0768: A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761.
nvd
CVE-2019-0762MEDIUMCVSS 4.3v112019-04-09
CVE-2019-0762 [MEDIUM] CWE-863 CVE-2019-0762: A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.
nvd
CVE-2019-0835MEDIUMCVSS 6.5v10v112019-04-09
CVE-2019-0835 [MEDIUM] CVE-2019-0835: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory, aka 'Microsoft Scripting Engine Information Disclosure Vulnerability'.
nvd
CVE-2019-0761MEDIUMCVSS 6.5v10v112019-04-09
CVE-2019-0761 [MEDIUM] CWE-863 CVE-2019-0761: A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct
A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0768.
nvd
CVE-2019-0665HIGHCVSS 7.5v10v112019-04-08
CVE-2019-0665 [HIGH] CWE-787 CVE-2019-0665: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0666, CVE-2019-0667, CVE-2019-0772.
nvd
CVE-2019-0609HIGHCVSS 7.5v112019-04-08
CVE-2019-0609 [HIGH] CWE-787 CVE-2019-0609: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.
nvd
CVE-2019-0639HIGHCVSS 7.5v112019-04-08
CVE-2019-0639 [HIGH] CVE-2019-0639: A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.
nvd
CVE-2019-0666HIGHCVSS 7.5v9v10+1 more2019-04-08
CVE-2019-0666 [HIGH] CVE-2019-0666: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0667, CVE-2019-0772.
nvd
CVE-2019-0667HIGHCVSS 7.5PoCv9v10+1 more2019-04-08
CVE-2019-0667 [HIGH] CVE-2019-0667: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0772.
nvd
CVE-2019-0606HIGHCVSS 7.5v112019-03-05
CVE-2019-0606 [HIGH] CWE-787 CVE-2019-0606: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
nvd
CVE-2019-0676MEDIUMCVSS 6.5KEVv10v112019-03-05
CVE-2019-0676 [MEDIUM] CVE-2019-0676: An information disclosure vulnerability exists when Internet Explorer improperly handles objects in
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
nvd
CVE-2019-0654MEDIUMCVSS 4.3v10v11+1 more2019-03-05
CVE-2019-0654 [MEDIUM] CVE-2019-0654: A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka '
A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'.
nvd
CVE-2019-0541HIGHCVSS 8.8KEVPoCv11v9+1 more2019-01-08
CVE-2019-0541 [HIGH] CWE-77 CVE-2019-0541: A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
nvd
CVE-2018-8653HIGHCVSS 7.5KEVv9v10+1 more2018-12-20
CVE-2018-8653 [HIGH] CVE-2018-8653: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.
nvd
CVE-2018-8631HIGHCVSS 7.5PoCv9v10+1 more2018-12-12
CVE-2018-8631 [HIGH] CWE-787 CVE-2018-8631: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
nvd