Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 59 of 80
CVE-2007-3092P3CRITICALCVSS 9.3v6.02007-06-06
CVE-2007-3092 [CRITICAL] CVE-2007-3092: Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties incl
Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties including SSL certificates, by interrupting page loading through certain use of location DOM objects and setTimeout calls. NOTE: this issue can be leveraged for phishing and other attacks.
nvd
CVE-2009-1335P4MEDIUMCVSS 4.3PoCv7v82009-04-17
CVE-2009-1335 [MEDIUM] CVE-2009-1335: Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denia
Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.
nvd
CVE-2017-11856P3HIGHCVSS 7.5v112017-11-15
CVE-2017-11856 [HIGH] CVE-2017-11856: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka
nvd
CVE-2005-4717P4MEDIUMCVSS 5.0PoCv6.02005-12-31
CVE-2005-4717 [MEDIUM] CVE-2005-4717: Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contain
nvd
CVE-2007-3091P3HIGHCVSS 7.1v6v7.02007-06-06
CVE-2007-3091 [HIGH] CWE-362 CVE-2007-3091: Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for
Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the content of the new page, as demonst
nvd
CVE-1999-0877P4MEDIUMCVSS 4.3PoCv4.01v5.01999-10-01
CVE-1999-0877 [MEDIUM] CWE-200 CVE-1999-0877: Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFR
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
nvd
CVE-1999-1241P3CRITICALCVSS 10.0v6.0.29001999-05-06
CVE-1999-1241 [CRITICAL] CVE-1999-1241: Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrar
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.
nvd
CVE-2006-3915P4MEDIUMCVSS 5.0PoCv6.02006-07-28
CVE-2006-3915 [MEDIUM] CVE-2006-3915: Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.
nvd
CVE-2006-3511P4MEDIUMCVSS 5.0PoCv6.02006-07-11
CVE-2006-3511 [MEDIUM] CVE-2006-3511: Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) b
Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the fonts property of the HtmlDlgSafeHelper object, which triggers a null dereference.
nvd
CVE-2006-3639P3HIGHCVSS 7.5v5.012006-08-09
CVE-2006-3639 [HIGH] CVE-2006-3639: Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when h
Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages and possibly execute code via unspecified vectors involving a crafted web page, aka "Source Element Cross-Domain Vulnerability."
nvd
CVE-2015-1748P3MEDIUMCVSS 6.8v7v8+3 more2015-06-10
CVE-2015-1748 [MEDIUM] CVE-2015-1748: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1743.
nvd
CVE-2000-0329P4MEDIUMCVSS 5.1PoCv4.01999-11-11
CVE-2000-0329 [MEDIUM] CVE-2000-0329: A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an atta
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
nvd
CVE-1999-0669P4MEDIUMCVSS 4.0PoCv4.0v5.01999-09-01
CVE-1999-0669 [MEDIUM] CVE-1999-0669: The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a r
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
nvd
CVE-2006-3898P4MEDIUMCVSS 5.0PoCv6.02006-07-27
CVE-2006-3898 [MEDIUM] CVE-2006-3898: Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of servi
Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method of the Internet.HHCtrl.1 ActiveX object before initializing the URL, which triggers a null dereference.
nvd
CVE-2006-3605P4MEDIUMCVSS 5.0PoCv6.02006-07-18
CVE-2006-3605 [MEDIUM] CVE-2006-3605: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by settin
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.
nvd
CVE-2006-3512P4MEDIUMCVSS 5.0PoCv6.02006-07-11
CVE-2006-3512 [MEDIUM] CVE-2006-3512: Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by se
Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX object to true, which triggers a null dereference.
nvd
CVE-2007-3893P3MEDIUMCVSS 6.8v5.00.2516.1900v5.00.2614.3500+24 more2007-10-09
CVE-2007-3893 [MEDIUM] CWE-399 CVE-2007-3893: Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to e
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via unspecified vectors involving memory corruption from an unhandled error.
nvd
CVE-2007-3550P3HIGHCVSS 7.8v6.0v7.02007-07-03
CVE-2007-3550 [HIGH] CWE-94 CVE-2007-3550: Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains
Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been dispu
nvd
CVE-2001-0643P4MEDIUMCVSS 5.0PoCv5.52001-09-20
CVE-2001-0643 [MEDIUM] CVE-2001-0643: Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name,
Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.
nvd
CVE-2016-3277P3MEDIUMCVSS 5.3v10v112016-07-13
CVE-2016-3277 [MEDIUM] CWE-200 CVE-2016-3277: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd