cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 57 of 80
CVE-2014-4066P3HIGHCVSS 7.5v112018-02-08
CVE-2014-4066 [HIGH] CVE-2014-4066: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2787, CVE-2014-2790, CVE-2014-2802, and CVE-2014-2806.
nvd
CVE-2009-0369P4MEDIUMCVSS 4.3PoCv72009-01-30
CVE-2009-0369 [MEDIUM] CVE-2009-0369: Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.
nvd
CVE-2019-0884P3HIGHCVSS 7.5v9v10+1 more2019-05-16
CVE-2019-0884 [HIGH] CWE-787 CVE-2019-0884: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0911, CVE-2019-0918.
nvd
CVE-2001-0089P4LOWCVSS 2.6PoC≤ 5.5v5.0+1 more2001-02-16
CVE-2001-0089 [LOW] CVE-2001-0089: Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client vi Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.
nvd
CVE-2019-1104P3HIGHCVSS 7.5v9v10+1 more2019-07-15
CVE-2019-1104 [HIGH] CWE-787 CVE-2019-1104: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in me A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
nvd
CVE-2017-8519P3HIGHCVSS 7.5v9v10+1 more2017-06-15
CVE-2017-8519 [HIGH] CWE-119 CVE-2017-8519: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is u
nvd
CVE-2017-8547P3HIGHCVSS 7.5v10v112017-06-15
CVE-2017-8547 [HIGH] CVE-2017-8547: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from C
nvd
CVE-2002-0976P4MEDIUMCVSS 6.4PoCv4.0v4.0.1+4 more2002-09-24
CVE-2002-0976 [MEDIUM] CVE-2002-0976: Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.
nvd
CVE-2002-1688P4MEDIUMCVSS 5.0PoCv5.5v6.02002-12-31
CVE-2002-1688 [MEDIUM] CVE-2002-1688: The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers t The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back button.
nvd
CVE-2011-0038P3CRITICALCVSS 9.3v82011-02-10
CVE-2011-0038 [CRITICAL] CVE-2011-0038: Untrusted search path vulnerability in Microsoft Internet Explorer 8 might allow local users to gain Untrusted search path vulnerability in Microsoft Internet Explorer 8 might allow local users to gain privileges via a Trojan horse IEShims.dll in the current working directory, as demonstrated by a Desktop directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
nvd
CVE-2011-2019P3CRITICALCVSS 9.3v92011-12-14
CVE-2011-2019 [CRITICAL] CWE-426 CVE-2011-2019: Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
nvd
CVE-2011-1257P3HIGHCVSS 7.6v6v7+1 more2011-08-10
CVE-2011-1257 [HIGH] CWE-362 CVE-2011-1257: Race condition in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitra Race condition in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors involving access to an object, aka "Window Open Race Condition Vulnerability."
nvd
CVE-2019-1055P3HIGHCVSS 7.5v10v11+1 more2019-06-12
CVE-2019-1055 [HIGH] CWE-787 CVE-2019-1055: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as th
nvd
CVE-2019-1005P3HIGHCVSS 7.5v9v10+1 more2019-06-12
CVE-2019-1005 [HIGH] CWE-787 CVE-2019-1005: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as th
nvd
CVE-2019-1080P3HIGHCVSS 7.5v9v10+1 more2019-06-12
CVE-2019-1080 [HIGH] CWE-787 CVE-2019-1080: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as th
nvd
CVE-2007-3826P3CRITICALCVSS 9.3v72007-07-17
CVE-2007-3826 [CRITICAL] CVE-2007-3826: Microsoft Internet Explorer 7 on Windows XP SP2 allows remote attackers to prevent users from leavin Microsoft Internet Explorer 7 on Windows XP SP2 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via repeated document.open function calls after a user requests a new page, but before the onBeforeUnload function is called.
nvd
CVE-2007-2291P3HIGHCVSS 7.5v7.0.5730.112007-04-26
CVE-2007-2291 [HIGH] CVE-2007-2291: CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7. CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows remote attackers to conduct HTTP response splitting attacks via a LF (%0a) in the username attribute.
nvd
CVE-2007-5344P3MEDIUMCVSS 6.8v5v5.01+13 more2007-12-12
CVE-2007-5344 [MEDIUM] CVE-2007-5344: Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a c Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption, related to uninitialized or deleted objects, a different issue than CVE-2007-3902 and CVE-2007-3903, and a va
nvd
CVE-2008-1544P3HIGHCVSS 7.1v5.01v6+1 more2008-03-28
CVE-2008-1544 [HIGH] CWE-20 CVE-2008-1544: The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length he
nvd
CVE-2002-2031P4MEDIUMCVSS 5.0PoCv5.0v5.0.1+2 more2002-12-31
CVE-2002-2031 [MEDIUM] CVE-2002-2031: Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to de Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase