cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 5 of 80
CVE-2017-11869P2HIGHCVSS 7.5Exploitedv112017-11-15
CVE-2017-11869 [HIGH] CVE-2017-11869: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Microsoft browsers handle objects in memory, aka
nvd
CVE-2018-8122P2HIGHCVSS 7.5Exploitedv112018-05-09
CVE-2018-8122 [HIGH] CVE-2018-8122: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8
nvd
CVE-2018-8114P2HIGHCVSS 7.5Exploitedv112018-05-09
CVE-2018-8114 [HIGH] CVE-2018-8114: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8
nvd
CVE-2006-3643P2MEDIUMCVSS 6.0Exploitedv5.012006-08-09
CVE-2006-3643 [MEDIUM] CWE-79 CVE-2006-3643: Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 S Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
nvd
CVE-2017-8750P2HIGHCVSS 7.5Exploitedv112017-09-13
CVE-2017-8750 [HIGH] CWE-119 CVE-2017-8750: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browsers acce
nvd
CVE-2011-0094P2CRITICALCVSS 9.3Exploitedv6v72011-04-13
CVE-2011-0094 [CRITICAL] CWE-399 CVE-2011-0094: Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execu Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layouts Handling Memory Corruption Vulnerability."
nvd
CVE-2004-0839P2MEDIUMCVSS 5.0Exploitedv5.0.1v5.5+1 more2004-08-18
CVE-2004-0839 [MEDIUM] CVE-2004-0839: Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attack Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
nvd
CVE-2007-5347P2MEDIUMCVSS 6.8Exploitedv5v5.01+13 more2007-12-12
CVE-2007-5347 [MEDIUM] CWE-399 CVE-2007-5347: Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "un Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."
nvd
CVE-2009-3674P2CRITICALCVSS 9.3Exploitedv5.0.1v6+2 more2009-12-09
CVE-2009-3674 [CRITICAL] CVE-2009-3674: Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attack Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.
nvd
CVE-2001-0154P2HIGHCVSS 7.5Exploited≤ 5.5v5.012001-05-03
CVE-2001-0154 [HIGH] CVE-2001-0154: HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
nvd
CVE-2016-3213P2HIGHCVSS 8.8PoCv9v10+1 more2016-06-16
CVE-2016-3213 [HIGH] CWE-264 CVE-2016-3213: The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an improper fallback mechanism, which allows remote attackers to gain privileges via N
nvd
CVE-2006-3227P2LOWCVSS 2.6Exploitedv6.0.29002006-06-26
CVE-2006-3227 [LOW] CVE-2006-3227: Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters via ASCII characters with the 8th bit set, which could be stripped by Internet Explorer to render legible text, b
nvd
CVE-2017-8636P2HIGHCVSS 7.5PoCv10v11+1 more2017-08-08
CVE-2017-8636 [HIGH] CVE-2017-8636: Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows R Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling obje
nvd
CVE-2017-8641P2HIGHCVSS 7.5PoCv9v10+1 more2017-08-08
CVE-2017-8641 [HIGH] CVE-2017-8641: Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows R Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render when handling objects in m
nvd
CVE-2014-1762P2HIGHCVSS 7.5PoCv6v7+4 more2014-04-27
CVE-2014-1762 [HIGH] CVE-2014-1762: Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to exe Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun competition at CanSecWest 2014.
nvd
CVE-2018-8631P2HIGHCVSS 7.5PoCv9v10+1 more2018-12-12
CVE-2018-8631 [HIGH] CWE-787 CVE-2018-8631: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2016-0041P2HIGHCVSS 7.8PoCv10v112016-02-10
CVE-2016-0041 [HIGH] CVE-2016-0041: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
nvd
CVE-2018-8353P2HIGHCVSS 7.5PoCv11v10+1 more2018-08-15
CVE-2018-8353 [HIGH] CWE-416 CVE-2018-8353: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-
nvd
CVE-2010-0805P2CRITICALCVSS 9.3PoCv5.01v62010-03-31
CVE-2010-0805 [CRITICAL] CWE-94 CVE-2010-0805: The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."
nvd
CVE-2017-11907P2HIGHCVSS 7.5PoCv11v10+1 more2017-12-12
CVE-2017-11907 [HIGH] CVE-2017-11907: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corr
nvd
Microsoft Internet Explorer vulnerabilities | cvebase