cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 53 of 80
CVE-2002-0189P4HIGHCVSS 7.5PoCv5.0v5.5+1 more2002-05-29
CVE-2002-0189 [HIGH] CVE-2002-0189: Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scrip Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.
nvd
CVE-2006-5579P3CRITICALCVSS 9.3v62006-12-12
CVE-2006-5579 [CRITICAL] CWE-119 CVE-2006-5579: Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka "Script Error Handling Memory Corruption Vulnerability."
nvd
CVE-2001-0150P4MEDIUMCVSS 5.1PoC≤ 5.52001-06-02
CVE-2001-0150 [MEDIUM] CWE-88 CVE-2001-0150: Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are spe Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
nvd
CVE-2019-0609P3HIGHCVSS 7.5v112019-04-08
CVE-2019-0609 [HIGH] CWE-787 CVE-2019-0609: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.
nvd
CVE-2018-8357P3HIGHCVSS 8.3v112018-08-15
CVE-2018-8357 [HIGH] CVE-2018-8357: An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "M An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege Vulnerability." This affects Internet Explorer 11, Microsoft Edge.
nvd
CVE-2016-1098P3HIGHCVSS 7.5v10v112016-05-11
CVE-2016-1098 [HIGH] CVE-2016-1098: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1100P3HIGHCVSS 7.5v10v112016-05-11
CVE-2016-1100 [HIGH] CVE-2016-1100: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1099P3HIGHCVSS 7.5v10v112016-05-11
CVE-2016-1099 [HIGH] CVE-2016-1099: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-1999-0668P4MEDIUMCVSS 5.1PoCv4.0v5.01999-08-21
CVE-1999-0668 [MEDIUM] CVE-1999-0668: The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
nvd
CVE-2019-0753P3HIGHCVSS 7.5v11v102019-04-09
CVE-2019-0753 [HIGH] CVE-2019-0753: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0752, CVE-2019-0862.
nvd
CVE-2020-0768P3HIGHCVSS 7.5v112020-03-12
CVE-2020-0768 [HIGH] CWE-787 CVE-2020-0768: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-08
nvd
CVE-2020-0830P3HIGHCVSS 7.5v112020-03-12
CVE-2020-0830 [HIGH] CVE-2020-0830: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-
nvd
CVE-2020-0832P3HIGHCVSS 7.5v11v92020-03-12
CVE-2020-0832 [HIGH] CVE-2020-0832: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0833,
nvd
CVE-2020-0833P3HIGHCVSS 7.5v112020-03-12
CVE-2020-0833 [HIGH] CVE-2020-0833: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832,
nvd
CVE-2003-1027P3CRITICALCVSS 10.0v5.0v5.0.1+2 more2004-01-20
CVE-2003-1027 [CRITICAL] CVE-2003-1027: Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and o Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and
nvd
CVE-2017-11813P3HIGHCVSS 7.5v112017-10-13
CVE-2017-11813 [HIGH] CWE-119 CVE-2017-11813: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user, due to how Internet Explorer handles objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from
nvd
CVE-2017-11901P3HIGHCVSS 7.5v11v102017-12-12
CVE-2017-11901 [HIGH] CVE-2017-11901: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corrupti
nvd
CVE-2007-5456P3HIGHCVSS 7.5≤ 72007-10-14
CVE-2007-5456 [HIGH] CVE-2007-5456: Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Sec Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary .exe files by placing a '?' (question mark) followed by a non-.exe filename after the .exe filename, as demonstrated by (1) .txt, (2) .cda, (3) .log, (4) .dif, (5) .sol, (6) .htt, (7) .itpc, (8) .itms, (9) .dvr-ms,
nvd
CVE-2020-0895P3HIGHCVSS 7.5v9v112020-04-15
CVE-2020-0895 [HIGH] CVE-2020-0895: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.
nvd
CVE-2016-0104P3HIGHCVSS 7.5v102016-03-09
CVE-2016-0104 [HIGH] CWE-119 CVE-2016-0104: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase