Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 60 of 80
CVE-2006-2385P3HIGHCVSS 7.6v5.012006-06-13
CVE-2006-2385 [HIGH] CWE-94 CVE-2006-2385: Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.
nvd
CVE-2006-6311P4MEDIUMCVSS 5.0PoCv6.0.2900.21802006-12-06
CVE-2006-6311 [MEDIUM] CVE-2006-6311: Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a
Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.
nvd
CVE-2003-0815P3HIGHCVSS 7.5v5.0.1v5.5+1 more2004-02-03
CVE-2003-0815 [HIGH] CVE-2003-0815: Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arb
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, a
nvd
CVE-2003-0530P3HIGHCVSS 7.5v5.0.1v5.5+1 more2003-08-27
CVE-2003-0530 [HIGH] CVE-2003-0530: Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allo
Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.
nvd
CVE-2006-1192P4LOWCVSS 2.6PoCv62006-04-11
CVE-2006-1192 [LOW] CWE-20 CVE-2006-1192: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by sp
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability." NOTE: this is a different vulnerability than CVE-20
nvd
CVE-2000-0156P4MEDIUMCVSS 5.1PoCv4.0v4.0.1+2 more2000-02-16
CVE-2000-0156 [MEDIUM] CVE-2000-0156: Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outsi
Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.
nvd
CVE-2009-2350P4MEDIUMCVSS 4.3PoCv62009-07-07
CVE-2009-2350 [MEDIUM] CVE-2009-2350: Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh hea
Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312.
nvd
CVE-2006-3427P4MEDIUMCVSS 5.0PoCv6.02006-07-07
CVE-2006-3427 [MEDIUM] CVE-2006-3427: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declar
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.
nvd
CVE-2008-5551P4MEDIUMCVSS 4.3PoCv82008-12-12
CVE-2008-5551 [MEDIUM] CWE-79 CVE-2008-5551: The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS p
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
nvd
CVE-2014-4124P3MEDIUMCVSS 6.8v7v7.0.5730+4 more2014-10-15
CVE-2014-4124 [MEDIUM] CVE-2014-4124: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-4123.
nvd
CVE-2002-0461P4MEDIUMCVSS 5.0PoCv5.0.1v5.5+1 more2002-08-12
CVE-2002-0461 [MEDIUM] CVE-2002-0461: Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application c
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.
nvd
CVE-2006-3472P4MEDIUMCVSS 5.0PoCv6.02006-07-10
CVE-2006-3472 [MEDIUM] CVE-2006-3472: Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via
Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with an A tag containing a long title attribute. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2015-1704P3MEDIUMCVSS 6.8v6v7+4 more2015-05-13
CVE-2015-1704 [MEDIUM] CVE-2015-1704: Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1703.
nvd
CVE-2015-1703P3MEDIUMCVSS 6.8v6v7+4 more2015-05-13
CVE-2015-1703 [MEDIUM] CWE-264 CVE-2015-1703: Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1704.
nvd
CVE-2010-0488P3MEDIUMCVSS 6.5v7v6+1 more2010-03-31
CVE-2010-0488 [MEDIUM] CWE-200 CVE-2010-0488: Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."
nvd
CVE-2003-0446P4MEDIUMCVSS 4.3PoCv5.5v6.02003-07-24
CVE-2003-0446 [MEDIUM] CVE-2003-0446: Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also us
Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.
nvd
CVE-2015-1739P3MEDIUMCVSS 6.8v10v112015-06-10
CVE-2015-1739 [MEDIUM] CWE-264 CVE-2015-1739: Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web s
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2006-7065P4MEDIUMCVSS 5.0PoCv6v6.0+6 more2007-03-02
CVE-2006-7065 [MEDIUM] CVE-2006-7065: Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRA
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
nvd
CVE-2005-2831P3HIGHCVSS 7.5v5.0.1v5.5+1 more2005-12-14
CVE-2005-2831 [HIGH] CVE-2005-2831: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (a
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a
nvd
CVE-1999-0981P4MEDIUMCVSS 5.1PoC≤ 5.01v4.0.1+1 more1999-12-08
CVE-1999-0981 [MEDIUM] CWE-59 CVE-1999-0981: Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."
nvd