Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 66 of 80
CVE-2019-0764P4MEDIUMCVSS 6.5v10v11+1 more2019-04-09
CVE-2019-0764 [MEDIUM] CWE-88 CVE-2019-0764: A tampering vulnerability exists when Microsoft browsers do not properly validate input under specif
A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'.
nvd
CVE-2017-11919P4MEDIUMCVSS 5.3v112017-12-12
CVE-2017-11919 [MEDIUM] CVE-2017-11919: ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromi
nvd
CVE-2015-2483P4MEDIUMCVSS 5.0v10v112015-09-09
CVE-2015-2483 [MEDIUM] CWE-200 CVE-2015-2483: Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from p
Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Information Disclosure Vulnerability."
nvd
CVE-2016-7282P4MEDIUMCVSS 6.1v9v10+1 more2016-12-20
CVE-2016-7282 [MEDIUM] CWE-79 CVE-2016-7282: Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft E
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2007-5355P4MEDIUMCVSS 5.8v5.01v6+1 more2007-12-05
CVE-2007-5355 [MEDIUM] CVE-2007-5355: The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary D
The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three or more components is configured, resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain, which allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.
nvd
CVE-2005-0054P4MEDIUMCVSS 5.1v5.01v5.52005-05-02
CVE-2005-0054 [MEDIUM] CVE-2005-0054: Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."
nvd
CVE-2015-6161P4MEDIUMCVSS 4.3v7v8+3 more2015-12-09
CVE-2015-6161 [MEDIUM] CWE-200 CVE-2015-6161: Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to bypass the ASL
Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."
nvd
CVE-2019-0930P4MEDIUMCVSS 6.5v9v10+1 more2019-05-16
CVE-2019-0930 [MEDIUM] CVE-2019-0930: An information disclosure vulnerability exists when Internet Explorer improperly handles objects in
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
nvd
CVE-2003-0513P4HIGHCVSS 7.5v5.0.1v5.5+1 more2004-04-15
CVE-2003-0513 [HIGH] CVE-2003-0513: Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on
Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
nvd
CVE-2012-0012P4MEDIUMCVSS 4.3v92012-02-14
CVE-2012-0012 [MEDIUM] CWE-665 CVE-2012-0012: Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string obj
Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."
nvd
CVE-2016-3273P4MEDIUMCVSS 5.3v9v10+1 more2016-07-13
CVE-2016-3273 [MEDIUM] CWE-200 CVE-2016-3273: The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly rest
The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2016-3391P4MEDIUMCVSS 5.3v10v112016-10-14
CVE-2016-3391 [MEDIUM] CWE-200 CVE-2016-3391: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discov
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2015-1686P4MEDIUMCVSS 4.3v8v9+2 more2015-05-13
CVE-2015-1686 [MEDIUM] CWE-200 CVE-2015-1686: The Microsoft (1) VBScript 5.6 through 5.8 and (2) JScript 5.6 through 5.8 engines, as used in Inter
The Microsoft (1) VBScript 5.6 through 5.8 and (2) JScript 5.6 through 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript ASLR Bypass."
nvd
CVE-2010-1257P4MEDIUMCVSS 4.3v82010-06-08
CVE-2010-1257 [MEDIUM] CWE-79 CVE-2010-1257: Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPa
Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization.
nvd
CVE-2009-4073P4MEDIUMCVSS 5.0v5v6+2 more2009-11-24
CVE-2009-4073 [MEDIUM] CWE-200 CVE-2009-4073: The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a lo
The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of a PDF document that was generated from a local web page.
nvd
CVE-2016-3292P4MEDIUMCVSS 5.0v10v112016-09-14
CVE-2016-3292 [MEDIUM] CWE-20 CVE-2016-3292: Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows
Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2006-5884P4HIGHCVSS 7.5v5.1v5.52006-11-14
CVE-2006-5884 [HIGH] CVE-2006-5884: Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Expl
Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.
nvd
CVE-2004-1155P4HIGHCVSS 7.5v5.0.1v5.5+1 more2004-12-31
CVE-2004-1155 [HIGH] CVE-2004-1155: Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting c
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows
nvd
CVE-2004-1173P4HIGHCVSS 7.5v6.02004-12-31
CVE-2004-1173 [HIGH] CVE-2004-1173: Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object mode
Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog.
nvd
CVE-2003-0115P4HIGHCVSS 7.5v5.0.1v5.5+1 more2003-05-12
CVE-2003-0115 [HIGH] CVE-2003-0115: Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed dur
Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.
nvd