cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 62 of 80
CVE-1999-0793P4LOWCVSS 2.6PoCv4.0.1v5.01999-11-17
CVE-1999-0793 [LOW] CVE-1999-0793: Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
nvd
CVE-2003-0817P4HIGHCVSS 7.5v5.0.1v5.5+1 more2004-02-03
CVE-2003-0817 [HIGH] CVE-2003-0817: Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read ar Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.
nvd
CVE-2005-1211P4MEDIUMCVSS 5.1v6.0.29002005-06-14
CVE-2005-1211 [MEDIUM] CVE-2005-1211: Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote at Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.
nvd
CVE-2005-0056P4MEDIUMCVSS 5.1v5.01v5.52005-05-02
CVE-2005-0056 [MEDIUM] CVE-2005-0056: Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition For Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
nvd
CVE-2015-1713P3MEDIUMCVSS 6.8v112015-05-13
CVE-2015-1713 [MEDIUM] CWE-264 CVE-2015-1713: Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, ak Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2015-1688P3MEDIUMCVSS 6.8v7v8+3 more2015-05-13
CVE-2015-1688 [MEDIUM] CWE-264 CVE-2015-1688: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2010-3330P4MEDIUMCVSS 6.5v6v7+1 more2010-10-13
CVE-2010-3330 [MEDIUM] CWE-200 CVE-2010-3330: Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a d Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."
nvd
CVE-2006-0057P4HIGHCVSS 7.5v5.01v5.5+1 more2006-01-27
CVE-2006-0057 [HIGH] CVE-2006-0057: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054
nvd
CVE-2006-4687P3MEDIUMCVSS 5.1v5.1v5.52006-11-14
CVE-2006-4687 [MEDIUM] CWE-119 CVE-2006-4687: Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via cra Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
nvd
CVE-1999-1016P4MEDIUMCVSS 5.0PoCv5.01999-08-27
CVE-1999-1016 [MEDIUM] CVE-1999-1016: Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Expr Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
nvd
CVE-2014-2783P3MEDIUMCVSS 6.4v7v8+3 more2014-07-08
CVE-2014-2783 [MEDIUM] CWE-264 CVE-2014-2783: Microsoft Internet Explorer 7 through 11 does not prevent use of wildcard EV SSL certificates, which Microsoft Internet Explorer 7 through 11 does not prevent use of wildcard EV SSL certificates, which might allow remote attackers to spoof a trust level by leveraging improper issuance of a wildcard certificate by a recognized Certification Authority, aka "Extended Validation (EV) Certificate Security Feature Bypass Vulnerability."
nvd
CVE-2017-8592P3MEDIUMCVSS 6.5v9v10+1 more2017-07-11
CVE-2017-8592 [MEDIUM] CWE-200 CVE-2017-8592: Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security feature bypass vulnerability when they improperly handle redirect requests, aka "Microsoft Browser Security Feature Bypass".
nvd
CVE-2009-2668P3HIGHCVSS 7.8v6v72009-08-05
CVE-2009-2668 [HIGH] CVE-2009-2668: Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16473 allows remote attac Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16473 allows remote attackers to cause a denial of service (CPU consumption) via an XML document composed of a long series of start-tags with no corresponding end-tags, a related issue to CVE-2009-1232.
nvd
CVE-2015-6044P4MEDIUMCVSS 6.8v82015-10-14
CVE-2015-6044 [MEDIUM] CWE-264 CVE-2015-6044: Microsoft Internet Explorer 8 allows remote attackers to gain privileges via a crafted web site, as Microsoft Internet Explorer 8 allows remote attackers to gain privileges via a crafted web site, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2006-3729P4LOWCVSS 2.6PoCv6.02006-07-21
CVE-2006-3729 [LOW] CVE-2006-3729: DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attac DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, which leads to an integer overflow and a null dereference.
nvd
CVE-2017-0049P4MEDIUMCVSS 4.3v112017-03-17
CVE-2017-0049 [MEDIUM] CVE-2017-0049: The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive in The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0018, and CVE-2017-0037.
nvd
CVE-2002-1714P4MEDIUMCVSS 5.0PoCv5.0v5.5+1 more2002-12-31
CVE-2002-1714 [MEDIUM] CVE-2002-1714: Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (cr Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
nvd
CVE-2002-0190P4HIGHCVSS 7.5v5.01v5.5+1 more2002-05-29
CVE-2002-0190 [HIGH] CVE-2002-0190: Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code unde Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.
nvd
CVE-2015-2423P4MEDIUMCVSS 4.3v7v8+3 more2015-08-15
CVE-2015-2423 [MEDIUM] CWE-200 CVE-2015-2423: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint
nvd
CVE-2018-8351P3MEDIUMCVSS 6.5v11v102018-08-15
CVE-2018-8351 [MEDIUM] CWE-829 CVE-2018-8351: An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cro An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase