Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 63 of 80
CVE-2004-0867P4HIGHCVSS 7.5v6.02004-12-23
CVE-2004-0867 [HIGH] CWE-264 CVE-2004-0867: Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such a
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
nvd
CVE-2017-0008P4MEDIUMCVSS 4.3v9v10+1 more2017-03-17
CVE-2017-0008 [MEDIUM] CWE-200 CVE-2017-0008: Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009 and CVE-2017-0059.
nvd
CVE-2008-2947P4MEDIUMCVSS 6.8v5.01v6+1 more2008-06-30
CVE-2008-2947 [MEDIUM] CWE-284 CVE-2008-2947: Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers
Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Proper
nvd
CVE-2005-4827P3HIGHCVSS 7.5v6v6.0+4 more2005-12-31
CVE-2005-4827 [HIGH] CVE-2005-4827: Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origi
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy ser
nvd
CVE-2015-6088P4MEDIUMCVSS 4.3v9v10+1 more2015-11-11
CVE-2015-6088 [MEDIUM] CWE-200 CVE-2015-6088: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASL
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."
nvd
CVE-2003-1326P4HIGHCVSS 7.5v5.0.1v5.5+1 more2003-02-19
CVE-2003-1326 [HIGH] CVE-2003-1326: Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security
Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."
nvd
CVE-2015-2412P4MEDIUMCVSS 4.3v10v112015-07-14
CVE-2015-2412 [MEDIUM] CWE-20 CVE-2015-2412: Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a cr
Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2019-1238P4MEDIUMCVSS 6.4v11v10+1 more2019-10-10
CVE-2019-1238 [MEDIUM] CVE-2019-1238: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239.
nvd
CVE-2016-7281P3MEDIUMCVSS 5.3v10v112016-12-20
CVE-2016-7281 [MEDIUM] CWE-254 CVE-2016-7281: The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows re
The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Browser Security Feature Bypass Vulnerability."
nvd
CVE-2015-1743P4MEDIUMCVSS 5.1v7v8+3 more2015-06-10
CVE-2015-1743 [MEDIUM] CWE-367 CVE-2015-1743: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1748.
nvd
CVE-2008-3474P4MEDIUMCVSS 6.5v5.01v6+1 more2008-10-15
CVE-2008-3474 [MEDIUM] CWE-200 CVE-2008-3474: Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origi
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability."
nvd
CVE-2001-0727P4HIGHCVSS 7.5v5.5v6.02001-12-14
CVE-2001-0727 [HIGH] CVE-2001-0727: Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Dis
Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."
nvd
CVE-2019-1193P4MEDIUMCVSS 6.4v10v112019-08-14
CVE-2019-1193 [MEDIUM] CWE-787 CVE-2019-1193: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in me
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user
nvd
CVE-2002-1262P4HIGHCVSS 7.5v5.5v6.02002-12-18
CVE-2002-1262 [HIGH] CVE-2002-1262: Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which a
Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.
nvd
CVE-2005-2830P4MEDIUMCVSS 5.0v5.0.1v5.5+1 more2005-12-14
CVE-2005-2830 [MEDIUM] CVE-2005-2830: Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic A
Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."
nvd
CVE-2002-1705P4MEDIUMCVSS 5.0PoCv5.5v6.02002-12-31
CVE-2002-1705 [MEDIUM] CVE-2002-1705: Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (cr
Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.
nvd
CVE-2016-3326P4MEDIUMCVSS 5.3v9v10+1 more2016-08-09
CVE-2016-3326 [MEDIUM] CWE-200 CVE-2016-3326: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive informa
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3327.
nvd
CVE-2019-0835P3MEDIUMCVSS 6.5v10v112019-04-09
CVE-2019-0835 [MEDIUM] CVE-2019-0835: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory, aka 'Microsoft Scripting Engine Information Disclosure Vulnerability'.
nvd
CVE-2016-0194P4MEDIUMCVSS 5.3v10v112016-05-11
CVE-2016-0194 [MEDIUM] CWE-200 CVE-2016-0194: Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass file permissions and obtain
Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass file permissions and obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2003-0814P4HIGHCVSS 7.5v5.0.1v5.5+1 more2004-02-03
CVE-2003-0814 [HIGH] CVE-2003-0814: Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.
nvd