cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 61 of 80
CVE-2017-8529P3MEDIUMCVSS 6.5v11v9+1 more2017-06-15
CVE-2017-8529 [MEDIUM] CWE-119 CVE-2017-8529: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability".
nvd
CVE-2006-3354P4MEDIUMCVSS 5.0PoCv6v6.0+4 more2006-07-06
CVE-2006-3354 [MEDIUM] CVE-2006-3354: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by settin Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.
nvd
CVE-2002-0022P4HIGHCVSS 7.5v5.5v6.02002-03-08
CVE-2002-0022 [HIGH] CVE-2002-0022: Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 an Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.
nvd
CVE-2006-1992P4LOWCVSS 2.6PoCv6.0.29002006-04-25
CVE-2006-1992 [LOW] CWE-399 CVE-2006-1992: mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.
nvd
CVE-1999-1110P4MEDIUMCVSS 5.0PoCv5.01999-11-14
CVE-1999-1110 [MEDIUM] CVE-1999-1110: Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code w Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.
nvd
CVE-2007-3341P3CRITICALCVSS 10.0v5v6.0+1 more2007-06-21
CVE-2007-3341 [CRITICAL] CVE-2007-3341: Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote att Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217.
nvd
CVE-2003-0532P4HIGHCVSS 7.5v5.0.1v5.5+1 more2003-08-27
CVE-2003-0532 [HIGH] CVE-2003-0532: Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returne Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.
nvd
CVE-2013-2557P3HIGHCVSS 7.5v92013-03-11
CVE-2013-2557 [HIGH] CWE-119 CVE-2013-2557: The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
nvd
CVE-2002-2062P4MEDIUMCVSS 4.3PoCv5.5v6.02002-12-31
CVE-2002-2062 [MEDIUM] CVE-2002-2062: Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running o Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.
nvd
CVE-1999-0869P4LOWCVSS 2.6PoCv3.0v3.0.1+4 more1998-12-01
CVE-1999-0869 [LOW] CVE-1999-0869: Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of a Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
nvd
CVE-2014-2819P3MEDIUMCVSS 6.8v7v8+3 more2014-08-12
CVE-2014-2819 [MEDIUM] CWE-264 CVE-2014-2819: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2000-0028P4LOWCVSS 2.6PoCv3.0v3.0.2+8 more1999-12-23
CVE-2000-0028 [LOW] CVE-2000-0028: Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
nvd
CVE-2018-0949P3MEDIUMCVSS 6.5v10v11+1 more2018-07-11
CVE-2018-0949 [MEDIUM] CVE-2018-0949: A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles r A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2003-0823P4HIGHCVSS 7.5v5.0.1v5.5+1 more2004-02-03
CVE-2003-0823 [HIGH] CVE-2003-0823: Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and ot Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.
nvd
CVE-2001-0322P4MEDIUMCVSS 5.0PoCv4.02001-06-02
CVE-2001-0322 [MEDIUM] CVE-2001-0322: MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to caus MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
nvd
CVE-2017-0009P4MEDIUMCVSS 4.3v9v10+1 more2017-03-17
CVE-2017-0009 [MEDIUM] CWE-200 CVE-2017-0009: Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0011, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.
nvd
CVE-2003-0233P4HIGHCVSS 7.5v5.0.1v5.5+1 more2003-05-12
CVE-2003-0233 [HIGH] CVE-2003-0233: Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attac Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.
nvd
CVE-2000-0596P4HIGHCVSS 7.5v4.0.1v52000-06-27
CVE-2000-0596 [HIGH] CVE-2000-0596: Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is r Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.
nvd
CVE-1999-1094P4HIGHCVSS 7.5≤ 4.0.11999-12-31
CVE-1999-1094 [HIGH] CVE-1999-1094: Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary c Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."
nvd
CVE-2016-3245P3MEDIUMCVSS 6.5v9v10+1 more2016-07-13
CVE-2016-3245 [MEDIUM] CWE-284 CVE-2016-3245: Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP conn Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase