Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 56 of 80
CVE-2019-0780P3HIGHCVSS 7.5v10v112019-04-09
CVE-2019-0780 [HIGH] CWE-787 CVE-2019-0780: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in me
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
nvd
CVE-2007-3406P4MEDIUMCVSS 4.3PoCv62007-06-26
CVE-2007-3406 [MEDIUM] CVE-2007-3406: Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script tag; (2) data attribute of an object tag; (3) value attribute of a param tag; (4) background attribut
nvd
CVE-2019-1059P3HIGHCVSS 7.5v9v10+1 more2019-07-15
CVE-2019-1059 [HIGH] CVE-2019-1059: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1056.
nvd
CVE-2019-1004P3HIGHCVSS 7.5v9v10+1 more2019-07-15
CVE-2019-1004 [HIGH] CVE-2019-1004: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1056, CVE-2019-1059.
nvd
CVE-2019-1056P3HIGHCVSS 7.5v112019-07-15
CVE-2019-1056 [HIGH] CVE-2019-1056: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1059.
nvd
CVE-2017-11827P3HIGHCVSS 7.5v11v102017-11-15
CVE-2017-11827 [HIGH] CWE-119 CVE-2017-11827: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how M
nvd
CVE-2000-0465P4MEDIUMCVSS 5.1PoCv4.0v5.0+2 more2000-05-17
CVE-2000-0465 [MEDIUM] CVE-2000-0465: Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser windo
Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.
nvd
CVE-2020-1092P3HIGHCVSS 7.5v11v92020-05-21
CVE-2020-1092 [HIGH] CVE-2020-1092: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1062.
nvd
CVE-2000-0400P4HIGHCVSS 7.5PoCv52000-05-13
CVE-2000-0400 [HIGH] CWE-20 CVE-2000-0400: The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.
nvd
CVE-2007-4041P3MEDIUMCVSS 6.8v72007-07-27
CVE-2007-4041 [MEDIUM] CVE-2007-4041: Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote att
Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
nvd
CVE-2001-0722P4MEDIUMCVSS 6.4PoCv5.5v6.02001-12-06
CVE-2001-0722 [MEDIUM] CVE-2001-0722: Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."
nvd
CVE-2006-3899P4MEDIUMCVSS 5.0PoCv6.02006-07-27
CVE-2006-3899 [MEDIUM] CVE-2006-3899: Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of servi
Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid memory access inside the SysAllocStringLen function.
nvd
CVE-2006-2766P4LOWCVSS 2.6PoCv6.0v7.02006-06-02
CVE-2006-2766 [LOW] CVE-2006-2766: Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
nvd
CVE-2007-4042P3HIGHCVSS 7.5v72007-07-27
CVE-2007-4042 [HIGH] CVE-2007-4042: Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execut
Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
nvd
CVE-2004-0526P4MEDIUMCVSS 5.0PoCv5.0v5.0.1+2 more2004-08-06
CVE-2004-0526 [MEDIUM] CVE-2004-0526: Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL i
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
nvd
CVE-2002-0191P4MEDIUMCVSS 5.0PoCv5.01v5.5+1 more2002-05-29
CVE-2002-0191 [MEDIUM] CVE-2002-0191: Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that c
Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability.
nvd
CVE-2019-1194P3HIGHCVSS 7.5v10v11+1 more2019-08-14
CVE-2019-1194 [HIGH] CWE-787 CVE-2019-1194: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights a
nvd
CVE-2019-1038P3HIGHCVSS 7.5v10v112019-06-12
CVE-2019-1038 [HIGH] CWE-787 CVE-2019-1038: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in me
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
nvd
CVE-2019-1133P3HIGHCVSS 7.5v9v10+1 more2019-08-14
CVE-2019-1133 [HIGH] CWE-787 CVE-2019-1133: A remote code execution vulnerability exists in the way that the scripting engine handles objects in
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights a
nvd
CVE-2008-0090P4MEDIUMCVSS 5.0PoCv72008-01-04
CVE-2008-0090 [MEDIUM] CWE-119 CVE-2008-0090: A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a de
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.
nvd