Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 64 of 80
CVE-2017-8602P3MEDIUMCVSS 6.5v112017-07-11
CVE-2017-8602 [MEDIUM] CWE-20 CVE-2017-8602: Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows R
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
nvd
CVE-2018-8113P3MEDIUMCVSS 6.5v112018-06-14
CVE-2018-8113 [MEDIUM] CVE-2018-8113: A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark o
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
nvd
CVE-2001-0667P4HIGHCVSS 7.3≤ 6.02001-10-30
CVE-2001-0667 [HIGH] CVE-2001-0667: Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, al
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0
nvd
CVE-2016-0005P4MEDIUMCVSS 4.3v9v10+1 more2016-01-13
CVE-2016-0005 [MEDIUM] CWE-20 CVE-2016-0005: Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy vi
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2017-11834P4MEDIUMCVSS 5.3v11v9+1 more2017-11-15
CVE-2017-11834 [MEDIUM] CVE-2017-11834: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handl
nvd
CVE-2007-1094P4HIGHCVSS 7.8v7.02007-02-26
CVE-2007-1094 [HIGH] CVE-2007-1094: Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference
Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.
nvd
CVE-1999-1235P4MEDIUMCVSS 4.6PoCv5.01999-08-25
CVE-1999-1235 [MEDIUM] CVE-1999-1235: Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which co
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.
nvd
CVE-2010-0255P4MEDIUMCVSS 4.3v6v7+2 more2010-02-04
CVE-2010-0255 [MEDIUM] CVE-2010-0255: Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML loca
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerabilit
nvd
CVE-2011-1252P4MEDIUMCVSS 6.1v7v82011-06-16
CVE-2011-1252 [MEDIUM] CWE-79 CVE-2011-1252: Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microso
Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inje
nvd
CVE-2016-3267P4MEDIUMCVSS 5.3v9v10+1 more2016-10-14
CVE-2016-3267 [MEDIUM] CWE-200 CVE-2016-3267: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of unspecified files via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2013-3908P4MEDIUMCVSS 4.3v6v7+3 more2013-11-13
CVE-2013-3908 [MEDIUM] CWE-200 CVE-2013-3908: Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Or
Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2019-0746P4MEDIUMCVSS 6.5v10v11+1 more2019-04-09
CVE-2019-0746 [MEDIUM] CVE-2019-0746: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.
nvd
CVE-2003-1505P4MEDIUMCVSS 4.3PoCv62003-12-31
CVE-2003-1505 [MEDIUM] CVE-2003-1505: Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by crea
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.
nvd
CVE-2012-1545P4MEDIUMCVSS 5.8v6.0v6.00.2462.0000+22 more2012-03-09
CVE-2012-1545 [MEDIUM] CWE-119 CVE-2012-1545: Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
nvd
CVE-2015-1692P4MEDIUMCVSS 4.3v7v8+3 more2015-05-13
CVE-2015-1692 [MEDIUM] CWE-200 CVE-2015-1692: Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard
Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard contents via crafted web script, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."
nvd
CVE-2003-1048P4HIGHCVSS 7.8v5.01v5.5+1 more2004-07-27
CVE-2003-1048 [HIGH] CWE-415 CVE-2003-1048: Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
nvd
CVE-2016-7278P4MEDIUMCVSS 5.3v9v10+1 more2016-12-20
CVE-2016-7278 [MEDIUM] CWE-200 CVE-2016-7278: Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information fro
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Hyperlink Object Library Information Disclosure Vulnerability."
nvd
CVE-2014-6340P4MEDIUMCVSS 4.3v6v7+4 more2014-11-11
CVE-2014-6340 [MEDIUM] CWE-200 CVE-2014-6340: Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1
Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
nvd
CVE-2017-0064P4MEDIUMCVSS 6.5v9v10+1 more2017-05-12
CVE-2017-0064 [MEDIUM] CVE-2017-0064: A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed Content warnings, aka "Internet Explorer Security Feature Bypass Vulnerability."
nvd
CVE-2016-3329P4MEDIUMCVSS 5.3v9v10+1 more2016-08-09
CVE-2016-3329 [MEDIUM] CWE-200 CVE-2016-3329: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence of files via a crafted webpage, aka "Internet Explorer Information Disclosure Vulnerability."
nvd