Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 50 of 80
CVE-2015-6162P3CRITICALCVSS 9.3v102015-12-09
CVE-2015-6162 [CRITICAL] CVE-2015-6162: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6152.
nvd
CVE-2006-4697P3CRITICALCVSS 9.3v5.01v6.0+1 more2007-02-13
CVE-2006-4697 [CRITICAL] CVE-2006-4697: Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX co
Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.
nvd
CVE-2017-8747P3HIGHCVSS 7.5v10v112017-09-13
CVE-2017-8747 [HIGH] CWE-119 CVE-2017-8747: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Internet Explorer accesses objects in memory, aka "Internet E
nvd
CVE-2017-8749P3HIGHCVSS 7.5v10v112017-09-13
CVE-2017-8749 [HIGH] CVE-2017-8749: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Internet Explorer accesses objects in memory, aka "Internet E
nvd
CVE-2006-1626P4MEDIUMCVSS 4.3PoCv6.02006-04-05
CVE-2006-1626 [MEDIUM] CVE-2006-1626: Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar
Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading. NOTE: this is a different vulnerability than CVE-2006
nvd
CVE-2018-8643P3HIGHCVSS 7.5v9v10+1 more2018-12-12
CVE-2018-8643 [HIGH] CWE-787 CVE-2018-8643: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2008-4260P3HIGHCVSS 8.5v5.01v6+1 more2008-12-10
CVE-2008-4260 [HIGH] CWE-399 CVE-2008-4260: Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote att
Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2014-8985P3HIGHCVSS 7.5v112018-02-08
CVE-2014-8985 [HIGH] CVE-2014-8985: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2811, CVE-2014-2822, CVE-2014-2823, CVE-2014-4057, and CVE-2014-4145.
nvd
CVE-2016-0159P3HIGHCVSS 7.5v92016-04-12
CVE-2016-0159 [HIGH] CWE-119 CVE-2016-0159: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2018-8118P3HIGHCVSS 7.5v10v112018-04-19
CVE-2018-8118 [HIGH] CWE-787 CVE-2018-8118: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2008-2255P3CRITICALCVSS 9.3v5.01v6+1 more2008-08-13
CVE-2008-2255 [CRITICAL] CVE-2008-2255: Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory, which allows remote attack
Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, a different vulnerability than CVE-2008-2254, aka "HTML Object Memory Corruption Vulnerability."
nvd
CVE-2017-8607P3HIGHCVSS 7.5v9v10+1 more2017-07-11
CVE-2017-8607 [HIGH] CVE-2017-8607: Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.
Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft br
nvd
CVE-2017-8606P3HIGHCVSS 7.5v9v10+1 more2017-07-11
CVE-2017-8606 [HIGH] CVE-2017-8606: Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.
Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft br
nvd
CVE-2017-8608P3HIGHCVSS 7.5v9v10+1 more2017-07-11
CVE-2017-8608 [HIGH] CVE-2017-8608: Microsoft browsers in Microsoft Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows
Microsoft browsers in Microsoft Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka
nvd
CVE-2016-3295P3HIGHCVSS 7.5v10v112016-09-14
CVE-2016-3295 [HIGH] CWE-119 CVE-2016-3295: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2017-11930P3HIGHCVSS 7.5v112017-12-12
CVE-2017-11930 [HIGH] CVE-2017-11930: ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scrip
nvd
CVE-2017-11913P3HIGHCVSS 7.5v11v10+1 more2017-12-12
CVE-2017-11913 [HIGH] CVE-2017-11913: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine
nvd
CVE-2016-3331P3HIGHCVSS 7.5v112016-10-14
CVE-2016-3331 [HIGH] CWE-119 CVE-2016-3331: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2016-7196P3HIGHCVSS 7.5v10v112016-11-10
CVE-2016-7196 [HIGH] CWE-119 CVE-2016-7196: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2017-8522P3HIGHCVSS 7.5v11v102017-06-15
CVE-2017-8522 [HIGH] CVE-2017-8522: Microsoft browsers in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows
Microsoft browsers in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka "Scripting Engine M
nvd