cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 51 of 80
CVE-2020-0847P3HIGHCVSS 7.5v11v92020-03-12
CVE-2020-0847 [HIGH] CVE-2020-0847: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
nvd
CVE-2016-3242P3HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3242 [HIGH] CVE-2016-3242: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3240 and CVE-2016-3241.
nvd
CVE-2016-3240P3HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3240 [HIGH] CWE-119 CVE-2016-3240: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3241 and CVE-2016-3242.
nvd
CVE-2016-0103P3HIGHCVSS 7.5v112016-03-09
CVE-2016-0103 [HIGH] CVE-2016-0103: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0102, CVE-2016-0106, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114.
nvd
CVE-2017-0040P3HIGHCVSS 7.5v9v10+1 more2017-03-17
CVE-2017-0040 [HIGH] CWE-119 CVE-2017-0040: The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerability is different from that described in CVE-2017-0130.
nvd
CVE-2016-3241P3HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3241 [HIGH] CVE-2016-3241: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3240 and CVE-2016-3242.
nvd
CVE-2020-0824P3HIGHCVSS 7.5v112020-03-12
CVE-2020-0824 [HIGH] CWE-787 CVE-2020-0824: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
nvd
CVE-2019-1063P3HIGHCVSS 7.5v9v10+1 more2019-07-15
CVE-2019-1063 [HIGH] CWE-787 CVE-2019-1063: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
nvd
CVE-2017-0018P3HIGHCVSS 7.5v10v112017-03-17
CVE-2017-0018 [HIGH] CWE-119 CVE-2017-0018: Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a de Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0037 and CVE-2017-0149.
nvd
CVE-2019-1371P3HIGHCVSS 7.5v9v10+1 more2019-10-10
CVE-2019-1371 [HIGH] CWE-787 CVE-2019-1371: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
nvd
CVE-2018-8457P3HIGHCVSS 7.5v11v102018-09-13
CVE-2018-8457 [HIGH] CVE-2018-8457: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8456, CVE-2018-8459.
nvd
CVE-2005-0055P3HIGHCVSS 7.5v5.0.1v5.5+1 more2005-05-02
CVE-2005-0055 [HIGH] CVE-2005-0055: Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML me Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."
nvd
CVE-2014-6354P3HIGHCVSS 7.5v6v7+4 more2017-06-27
CVE-2014-6354 [HIGH] CWE-119 CVE-2014-6354: Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explore Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 allows remote attackers to execute arbitrary code.
nvd
CVE-1999-1577P4MEDIUMCVSS 5.1PoCv4.0.1v5.01999-10-31
CVE-1999-1577 [MEDIUM] CVE-1999-1577: Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allo Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.
nvd
CVE-2019-0639P3HIGHCVSS 7.5v112019-04-08
CVE-2019-0639 [HIGH] CVE-2019-0639: A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.
nvd
CVE-2019-0862P3HIGHCVSS 7.5v11v102019-04-09
CVE-2019-0862 [HIGH] CVE-2019-0862: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0752, CVE-2019-0753.
nvd
CVE-2020-0673P3HIGHCVSS 7.5v9v10+1 more2020-02-11
CVE-2020-0673 [HIGH] CWE-787 CVE-2020-0673: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
nvd
CVE-2017-0226P3HIGHCVSS 7.5v10v112017-05-12
CVE-2017-0226 [HIGH] CVE-2017-0226: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0222.
nvd
CVE-2008-2256P3CRITICALCVSS 9.3v5.01v6+1 more2008-08-13
CVE-2008-2256 [CRITICAL] CWE-20 CVE-2008-2256: Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrect Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2016-0166P3HIGHCVSS 7.5v112016-04-12
CVE-2016-0166 [HIGH] CWE-119 CVE-2016-0166: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase