cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 6 of 80
CVE-2018-8291P2HIGHCVSS 7.5PoCv112018-07-11
CVE-2018-8291 [HIGH] CVE-2018-8291: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8296, CVE-2018-8298.
nvd
CVE-2018-8288P2HIGHCVSS 7.5PoCv112018-07-11
CVE-2018-8288 [HIGH] CVE-2018-8288: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8291, CVE-2018-8296, CVE-2018-8298.
nvd
CVE-2018-8355P2HIGHCVSS 7.5PoCv112018-08-15
CVE-2018-8355 [HIGH] CVE-2018-8355: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8353, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, C
nvd
CVE-2016-7241P2HIGHCVSS 7.5PoCv112016-11-10
CVE-2016-7241 [HIGH] CWE-119 CVE-2016-7241: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2016-3247P2HIGHCVSS 7.5PoCv112016-09-14
CVE-2016-3247 [HIGH] CVE-2016-3247: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code o Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
nvd
CVE-2014-0307P2CRITICALCVSS 9.3PoCv92014-03-12
CVE-2014-0307 [CRITICAL] CWE-119 CVE-2014-0307: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-7287P2HIGHCVSS 7.5PoCv112016-12-20
CVE-2016-7287 [HIGH] CWE-119 CVE-2016-7287: The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2018-0935P2HIGHCVSS 7.5PoCv9v10+1 more2018-03-14
CVE-2018-0935 [HIGH] CVE-2018-0935: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is
nvd
CVE-2017-8635P2HIGHCVSS 7.5PoCv10v112017-08-08
CVE-2017-8635 [HIGH] CVE-2017-8635: Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows R Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that JavaScript engines render when handling objects in memory, aka "Script
nvd
CVE-2018-8145P2HIGHCVSS 7.5PoCv10v112018-05-09
CVE-2018-8145 [HIGH] CVE-2018-8145: An information disclosure vulnerability exists when Chakra improperly discloses the contents of its An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE
nvd
CVE-2018-0840P2HIGHCVSS 7.5PoCv11v102018-02-15
CVE-2018-0840 [HIGH] CVE-2018-0840: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Co
nvd
CVE-2012-1876P2CRITICALCVSS 9.3PoCv6v7+2 more2012-06-12
CVE-2012-1876 [CRITICAL] CWE-94 CVE-2012-1876: Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects i Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own co
nvd
CVE-2008-3013P2CRITICALCVSS 9.3PoCv62008-09-11
CVE-2008-3013 [CRITICAL] CWE-399 CVE-2008-3013: gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 an gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 20
nvd
CVE-2014-1773P2CRITICALCVSS 9.3PoCv9v10+1 more2014-06-11
CVE-2014-1773 [CRITICAL] CWE-119 CVE-2014-1773: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2
nvd
CVE-2013-0025P2CRITICALCVSS 9.3PoCv82013-02-13
CVE-2013-0025 [CRITICAL] CWE-399 CVE-2013-0025: Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."
nvd
CVE-2017-11810P2HIGHCVSS 7.5PoCv9v10+1 more2017-10-13
CVE-2017-11810 [HIGH] CVE-2017-11810: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engin
nvd
CVE-2007-5348P2CRITICALCVSS 9.3PoCv62008-09-11
CVE-2007-5348 [CRITICAL] CWE-189 CVE-2007-5348: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 S Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Serv
nvd
CVE-2017-11890P2HIGHCVSS 7.5PoCv11v10+1 more2017-12-12
CVE-2017-11890 [HIGH] CVE-2017-11890: Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Ser Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corruption Vul
nvd
CVE-2017-11793P2HIGHCVSS 7.5PoCv11v10+1 more2017-10-13
CVE-2017-11793 [HIGH] CVE-2017-11793: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engin
nvd
CVE-2016-0199P2HIGHCVSS 8.8PoCv9v10+1 more2016-06-16
CVE-2016-0199 [HIGH] CWE-119 CVE-2016-0199: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0200 and CVE-2016-3211.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase