cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 58 of 80
CVE-2006-3591P4MEDIUMCVSS 5.0PoCv6.02006-07-18
CVE-2006-3591 [MEDIUM] CVE-2006-3591: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application cras Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference.
nvd
CVE-2006-3638P3HIGHCVSS 7.5v5.0.1v6.02006-08-08
CVE-2006-3638 [HIGH] CWE-119 CVE-2006-3638: Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which all Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."
nvd
CVE-2003-0447P4MEDIUMCVSS 5.1PoCv5.01v5.5+1 more2003-07-24
CVE-2003-0447 [MEDIUM] CVE-2003-0447: The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.
nvd
CVE-2015-6047P3MEDIUMCVSS 6.8v8v9+2 more2015-10-14
CVE-2015-6047 [MEDIUM] CWE-264 CVE-2015-6047: The broker EditWith feature in Microsoft Internet Explorer 8 through 11 allows remote attackers to b The broker EditWith feature in Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the AppContainer protection mechanism and gain privileges via a DelegateExecute launch of an arbitrary application, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Internet Explorer Elevation of Privilege Vulnerability
nvd
CVE-1999-0487P4LOWCVSS 2.6PoCv4.0v5.01999-05-01
CVE-1999-0487 [LOW] CVE-1999-0487: The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.
nvd
CVE-2007-5158P4MEDIUMCVSS 4.3PoCv6.02007-10-01
CVE-2007-5158 [MEDIUM] CVE-2007-5158: The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attacker The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upload field, a related issue to CVE-2007-3511.
nvd
CVE-2003-1025P4MEDIUMCVSS 4.3PoCv6.02004-01-20
CVE-2003-1025 [MEDIUM] CWE-20 CVE-2003-1025: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01 Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
nvd
CVE-2017-8651P3HIGHCVSS 7.5v9v102017-08-08
CVE-2017-8651 [HIGH] CWE-119 CVE-2017-8651: Internet Explorer in Microsoft Windows Server 2008 SP2 and Windows Server 2012 allows an attacker to Internet Explorer in Microsoft Windows Server 2008 SP2 and Windows Server 2012 allows an attacker to execute arbitrary code in the context of the current user due to Internet Explorer improperly accessing objects in memory, aka "Internet Explorer Memory Corruption Vulnerability".
nvd
CVE-2007-3903P3MEDIUMCVSS 6.8v6v6.0+8 more2007-12-12
CVE-2007-3903 [MEDIUM] CVE-2007-3903: Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitiali Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-2007-5344, a variant of "Uninitialized Memory Corruption Vulnerability."
nvd
CVE-2002-1187P4MEDIUMCVSS 6.8PoCv5.0v5.0.1+2 more2002-12-11
CVE-2002-1187 [MEDIUM] CVE-2002-1187: Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attacke Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the or element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.
nvd
CVE-2015-2484P3MEDIUMCVSS 6.4v10v112015-09-09
CVE-2015-2484 [MEDIUM] CWE-264 CVE-2015-2484: Microsoft Internet Explorer 10 and 11 uses an incorrect flag during certain filesystem accesses, whi Microsoft Internet Explorer 10 and 11 uses an incorrect flag during certain filesystem accesses, which allows remote attackers to delete arbitrary files via unspecified vectors, aka "Tampering Vulnerability."
nvd
CVE-2006-1191P4MEDIUMCVSS 4.0PoCv5.01v5.1+2 more2006-04-11
CVE-2006-1191 [MEDIUM] CVE-2006-1191: Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is ass Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.
nvd
CVE-2009-2764P4MEDIUMCVSS 5.0PoCv8.0.7100.02009-08-14
CVE-2009-2764 [MEDIUM] CVE-2009-2764: Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers t Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.
nvd
CVE-2006-3513P4MEDIUMCVSS 5.0PoCv6.0v6.0.2600+3 more2006-07-11
CVE-2006-3513 [MEDIUM] CVE-2006-3513: danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (app danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.
nvd
CVE-2010-1117P3HIGHCVSS 7.6v8.0.60012010-03-25
CVE-2010-1117 [HIGH] CWE-119 CVE-2010-1117: Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
nvd
CVE-2006-6310P4MEDIUMCVSS 5.0PoC≤ 6.0v6.02006-12-06
CVE-2006-6310 [MEDIUM] CVE-2006-6310: Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2007-3892P3HIGHCVSS 7.5v5.00.2516.1900v5.00.2614.3500+24 more2007-10-09
CVE-2007-3892 [HIGH] CVE-2007-3892: Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826.
nvd
CVE-2009-2655P4MEDIUMCVSS 4.3PoCv7v82009-08-03
CVE-2009-2655 [MEDIUM] CWE-20 CVE-2009-2655: mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.
nvd
CVE-2007-0943P3MEDIUMCVSS 6.8v5.012007-08-14
CVE-2007-0943 [MEDIUM] CVE-2007-0943: Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arb Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.
nvd
CVE-2004-2383P4MEDIUMCVSS 5.1PoCv5.5v6.02004-12-31
CVE-2004-2383 [MEDIUM] CVE-2004-2383: Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categor
nvd
Microsoft Internet Explorer vulnerabilities | cvebase