Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 52 of 80
CVE-2020-1567P3HIGHCVSS 7.5v11v92020-08-17
CVE-2020-1567 [HIGH] CVE-2020-1567: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.
An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker cou
nvd
CVE-2018-8126P3HIGHCVSS 8.8v112018-05-09
CVE-2018-8126 [HIGH] CVE-2018-8126: A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Co
A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
nvd
CVE-2004-2090P4MEDIUMCVSS 5.0PoCv5.0.1v5.5+1 more2004-02-07
CVE-2004-2090 [MEDIUM] CVE-2004-2090: Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
nvd
CVE-2014-4145P3HIGHCVSS 7.5v112018-02-08
CVE-2014-4145 [HIGH] CVE-2014-4145: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2811, CVE-2014-2822, CVE-2014-2823, CVE-2014-4057, and CVE-2014-8985.
nvd
CVE-2017-11822P3HIGHCVSS 7.5v112017-10-13
CVE-2017-11822 [HIGH] CVE-2017-11822: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how Internet Explorer handles objects in memory, aka "Internet Explorer
nvd
CVE-2017-11894P3HIGHCVSS 7.5v11v10+1 more2017-12-12
CVE-2017-11894 [HIGH] CVE-2017-11894: ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Window
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and and Internet Explorer adn Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting
nvd
CVE-2017-11912P3HIGHCVSS 7.5v10v11+1 more2017-12-12
CVE-2017-11912 [HIGH] CVE-2017-11912: ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Window
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engi
nvd
CVE-2017-11895P3HIGHCVSS 7.5v112017-12-12
CVE-2017-11895 [HIGH] CVE-2017-11895: ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handl
nvd
CVE-2019-0665P3HIGHCVSS 7.5v10v112019-04-08
CVE-2019-0665 [HIGH] CWE-787 CVE-2019-0665: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0666, CVE-2019-0667, CVE-2019-0772.
nvd
CVE-2019-0995P3HIGHCVSS 8.8v112019-05-16
CVE-2019-0995 [HIGH] CVE-2019-0995: A security feature bypass vulnerability exists when urlmon.dll improperly handles certain Mark of th
A security feature bypass vulnerability exists when urlmon.dll improperly handles certain Mark of the Web queries, aka 'Internet Explorer Security Feature Bypass Vulnerability'.
nvd
CVE-2016-0154P3HIGHCVSS 7.5v9v10+1 more2016-04-12
CVE-2016-0154 [HIGH] CWE-119 CVE-2016-0154: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2016-0105P3HIGHCVSS 7.5v9v10+1 more2016-03-09
CVE-2016-0105 [HIGH] CWE-119 CVE-2016-0105: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113.
nvd
CVE-2016-0110P3HIGHCVSS 7.5v10v112016-03-09
CVE-2016-0110 [HIGH] CWE-119 CVE-2016-0110: Microsoft Internet Explorer 10 through 11 and Microsoft Edge allow remote attackers to execute arbit
Microsoft Internet Explorer 10 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2020-1215P3HIGHCVSS 7.5v11v92020-06-09
CVE-2020-1215 [HIGH] CVE-2020-1215: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
nvd
CVE-2020-1214P3HIGHCVSS 7.5v11v92020-06-09
CVE-2020-1214 [HIGH] CVE-2020-1214: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
nvd
CVE-2016-3264P3HIGHCVSS 7.5v9v10+1 more2016-07-13
CVE-2016-3264 [HIGH] CWE-119 CVE-2016-3264: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2019-1485P3HIGHCVSS 7.5v9v10+1 more2019-12-10
CVE-2019-1485 [HIGH] CWE-787 CVE-2019-1485: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
nvd
CVE-2016-3383P3HIGHCVSS 7.5v10v112016-10-14
CVE-2016-3383 [HIGH] CWE-119 CVE-2016-3383: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2016-3243P3HIGHCVSS 7.5v10v112016-07-13
CVE-2016-3243 [HIGH] CWE-119 CVE-2016-3243: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-0164P3HIGHCVSS 7.5v10v112016-04-12
CVE-2016-0164 [HIGH] CWE-119 CVE-2016-0164: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd