Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 54 of 80
CVE-2020-1213P3HIGHCVSS 7.5v11v92020-06-09
CVE-2020-1213 [HIGH] CWE-787 CVE-2020-1213: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
nvd
CVE-2020-1216P3HIGHCVSS 7.5v11v92020-06-09
CVE-2020-1216 [HIGH] CVE-2020-1216: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1230, CVE-2020-1260.
nvd
CVE-2020-1260P3HIGHCVSS 7.5v112020-06-09
CVE-2020-1260 [HIGH] CVE-2020-1260: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230.
nvd
CVE-2020-1093P3HIGHCVSS 7.5v11v92020-05-21
CVE-2020-1093 [HIGH] CVE-2020-1093: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1058, CVE-2020-1060.
nvd
CVE-2020-1035P3HIGHCVSS 7.5v9v112020-05-21
CVE-2020-1035 [HIGH] CWE-787 CVE-2020-1035: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1058, CVE-2020-1060, CVE-2020-1093.
nvd
CVE-2020-1230P3HIGHCVSS 7.5v11v92020-06-09
CVE-2020-1230 [HIGH] CVE-2020-1230: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1260.
nvd
CVE-2020-1060P3HIGHCVSS 7.5v9v112020-05-21
CVE-2020-1060 [HIGH] CVE-2020-1060: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1058, CVE-2020-1093.
nvd
CVE-2020-1058P3HIGHCVSS 7.5v9v112020-05-21
CVE-2020-1058 [HIGH] CVE-2020-1058: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1035, CVE-2020-1060, CVE-2020-1093.
nvd
CVE-2019-1239P3HIGHCVSS 7.5v112019-10-10
CVE-2019-1239 [HIGH] CVE-2019-1239: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1238.
nvd
CVE-2016-3384P3HIGHCVSS 7.5v9v10+1 more2016-10-14
CVE-2016-3384 [HIGH] CWE-119 CVE-2016-3384: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2019-1390P3HIGHCVSS 7.5v9v10+1 more2019-11-12
CVE-2019-1390 [HIGH] CVE-2019-1390: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
nvd
CVE-2019-0988P3HIGHCVSS 7.5v10v112019-06-12
CVE-2019-0988 [HIGH] CWE-787 CVE-2019-0988: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as th
nvd
CVE-2007-0099P3CRITICALCVSS 9.3v62007-01-08
CVE-2007-0099 [CRITICAL] CWE-362 CVE-2007-0099: Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynch
nvd
CVE-2020-1506P3HIGHCVSS 8.8v112020-09-11
CVE-2020-1506 [HIGH] CVE-2020-1506: <p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in
An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
There are multiple ways an attacker could exploit the vulnerability:
In a web-based attack scenario, an attacker could host a specially crafted website t
nvd
CVE-2006-3357P3HIGHCVSS 7.5v6.02006-07-06
CVE-2006-3357 [HIGH] CVE-2006-3357: Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
nvd
CVE-2006-3450P3HIGHCVSS 7.5v6.02006-08-08
CVE-2006-3450 [HIGH] CWE-20 CVE-2006-3450: Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the documen
Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file.
nvd
CVE-2013-3186P3HIGHCVSS 7.6v7v82013-08-14
CVE-2013-3186 [HIGH] CWE-264 CVE-2013-3186: The Protected Mode feature in Microsoft Internet Explorer 7 through 10 on Windows Vista SP2, Windows
The Protected Mode feature in Microsoft Internet Explorer 7 through 10 on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly implement the Integrity Access Level (aka IL) protection mechanism, which allows remote attackers to obtain medium-integrity privileges by leverag
nvd
CVE-2009-3019P4MEDIUMCVSS 5.0PoCv6v72009-08-31
CVE-2009-3019 [MEDIUM] CWE-94 CVE-2009-3019: Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows re
Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and then calls setAttribute to set the value attribute.
nvd
CVE-2006-3897P4MEDIUMCVSS 5.0PoCv6.02006-07-27
CVE-2006-3897 [MEDIUM] CWE-787 CVE-2006-3897: Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a d
Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
nvd
CVE-2008-2254P3CRITICALCVSS 9.3v6v72008-08-13
CVE-2008-2254 [CRITICAL] CWE-399 CVE-2008-2254: Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to
Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."
nvd