Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 65 of 80
CVE-2004-0484P4LOWCVSS 2.6PoCv6.0.29002004-07-07
CVE-2004-0484 [LOW] CVE-2004-0484: mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of serv
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.
nvd
CVE-2006-0830P4HIGHCVSS 7.5v6.0.29002006-02-21
CVE-2006-0830 [HIGH] CVE-2006-0830: The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (reso
The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location" variable within the loop.
nvd
CVE-2003-0531P4HIGHCVSS 7.5v5.0.1v5.5+1 more2003-08-27
CVE-2003-0531 [HIGH] CVE-2003-0531: Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in t
Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.
nvd
CVE-2014-0268P4MEDIUMCVSS 4.3v8v9+2 more2014-02-12
CVE-2014-0268 [MEDIUM] CWE-264 CVE-2014-0268: Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-k
Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-key creation, which allows remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2019-0761P4MEDIUMCVSS 6.5v10v112019-04-09
CVE-2019-0761 [MEDIUM] CWE-863 CVE-2019-0761: A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct
A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0768.
nvd
CVE-2002-0057P4MEDIUMCVSS 5.0v6.02002-03-08
CVE-2002-0057 [MEDIUM] CVE-2002-0057: XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zo
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
nvd
CVE-2017-11887P4MEDIUMCVSS 5.3v11v9+1 more2017-12-12
CVE-2017-11887 [MEDIUM] CWE-200 CVE-2017-11887: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handle objects in memory, aka
nvd
CVE-2015-6053P4MEDIUMCVSS 5.0v112015-10-14
CVE-2015-6053 [MEDIUM] CWE-200 CVE-2015-6053: Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process
Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via crafted parameters in an ArrayBuffer.slice call, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2014-4140P4MEDIUMCVSS 4.3v8v9+2 more2014-10-15
CVE-2014-4140 [MEDIUM] CWE-264 CVE-2014-4140: Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mecha
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
nvd
CVE-2014-6350P4MEDIUMCVSS 4.3v10v112014-11-11
CVE-2014-6350 [MEDIUM] CVE-2014-6350: Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web s
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6349.
nvd
CVE-2002-1444P4LOWCVSS 2.6PoCv5.5v6.02002-08-15
CVE-2002-1444 [LOW] CVE-2002-1444: The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to
The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.
nvd
CVE-2014-6345P4MEDIUMCVSS 4.3v9v102014-11-11
CVE-2014-6345 [MEDIUM] CWE-200 CVE-2014-6345: Microsoft Internet Explorer 9 and 10 allows remote attackers to read content from a different (1) do
Microsoft Internet Explorer 9 and 10 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
nvd
CVE-1999-1453P4LOWCVSS 2.6PoCv4.01999-02-02
CVE-1999-1453 [LOW] CVE-1999-1453: Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of t
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.
nvd
CVE-2002-0078P4HIGHCVSS 7.5v5.0.1v5.5+1 more2002-03-29
CVE-2002-0078 [HIGH] CVE-2002-0078: The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers t
The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.
nvd
CVE-2015-6164P4MEDIUMCVSS 6.8v9v10+1 more2015-12-09
CVE-2015-6164 [MEDIUM] CWE-20 CVE-2015-6164: Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protecti
Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability."
nvd
CVE-2016-3327P4MEDIUMCVSS 5.3v9v10+1 more2016-08-09
CVE-2016-3327 [MEDIUM] CVE-2016-3327: Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive informa
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3326.
nvd
CVE-2018-1000P4MEDIUMCVSS 5.3v10v11+1 more2018-04-12
CVE-2018-1000 [MEDIUM] CVE-2018-1000: An information disclosure vulnerability exists in the way that the scripting engine handles objects
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-0989.
nvd
CVE-2001-0002P4HIGHCVSS 7.5≤ 5.5v5.012001-07-21
CVE-2001-0002 [HIGH] CVE-2001-0002: Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
nvd
CVE-2016-3261P4MEDIUMCVSS 5.3v112016-07-13
CVE-2016-3261 [MEDIUM] CWE-200 CVE-2016-3261: Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information via a crafted
Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2018-0981P4MEDIUMCVSS 5.3v10v11+1 more2018-04-12
CVE-2018-0981 [MEDIUM] CWE-787 CVE-2018-0981: An information disclosure vulnerability exists in the way that the scripting engine handles objects
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0987, CVE-2018-0989, CVE-2018-1000.
nvd