Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 67 of 80
CVE-2007-4356P4CRITICALCVSS 9.3v6v72007-08-15
CVE-2007-4356 [CRITICAL] CVE-2007-4356: Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during a
Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during an FTP session, which allows context-dependent attackers to obtain sensitive information by reading the HTML source, as demonstrated by a (1) .htm, (2) .html, or (3) .mht file.
nvd
CVE-2004-0843P4MEDIUMCVSS 5.0v5.52004-11-03
CVE-2004-0843 [MEDIUM] CVE-2004-0843: Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attacke
Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
nvd
CVE-2019-0920P4MEDIUMCVSS 4.3v11v10+1 more2019-06-12
CVE-2019-0920 [MEDIUM] CWE-787 CVE-2019-0920: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as
nvd
CVE-2014-6328P4MEDIUMCVSS 5.0v8v9+2 more2014-12-11
CVE-2014-6328 [MEDIUM] CWE-20 CVE-2014-6328: Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a craf
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6365.
nvd
CVE-2005-4089P4HIGHCVSS 7.1v6.02005-12-08
CVE-2005-4089 [HIGH] CWE-264 CVE-2005-4089: Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and
Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulner
nvd
CVE-2015-1684P4MEDIUMCVSS 4.3v8v9+2 more2015-05-13
CVE-2015-1684 [MEDIUM] CWE-200 CVE-2015-1684: VBScript.dll in the Microsoft VBScript 5.6 through 5.8 engine, as used in Internet Explorer 8 throug
VBScript.dll in the Microsoft VBScript 5.6 through 5.8 engine, as used in Internet Explorer 8 through 11 and other products, allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript ASLR Bypass."
nvd
CVE-2000-0464P4HIGHCVSS 7.6v4.0v4.0.1+2 more2000-05-17
CVE-2000-0464 [HIGH] CVE-2000-0464: Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer ove
Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.
nvd
CVE-2002-0027P4HIGHCVSS 7.5v5.5v6.02002-03-08
CVE-2002-0027 [HIGH] CVE-2002-0027: Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the
Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.
nvd
CVE-2019-0921P4MEDIUMCVSS 6.5v9v10+1 more2019-05-16
CVE-2019-0921 [MEDIUM] CVE-2019-0921: An spoofing vulnerability exists when Internet Explorer improperly handles URLs, aka 'Internet Explo
An spoofing vulnerability exists when Internet Explorer improperly handles URLs, aka 'Internet Explorer Spoofing Vulnerability'.
nvd
CVE-2003-1028P4MEDIUMCVSS 5.0v5.0v5.0.1+2 more2004-01-20
CVE-2003-1028 [MEDIUM] CVE-2003-1028: The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directo
The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
nvd
CVE-2014-6339P4MEDIUMCVSS 5.0v8v92014-11-11
CVE-2014-6339 [MEDIUM] CWE-264 CVE-2014-6339: Microsoft Internet Explorer 8 and 9 allows remote attackers to bypass the ASLR protection mechanism
Microsoft Internet Explorer 8 and 9 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
nvd
CVE-2007-2292P4MEDIUMCVSS 4.3v7.0.5730.112007-04-26
CVE-2007-2292 [MEDIUM] CWE-20 CVE-2007-2292: CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8
CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.
nvd
CVE-2016-0059P4MEDIUMCVSS 4.3v9v10+1 more2016-02-10
CVE-2016-0059 [MEDIUM] CWE-200 CVE-2016-0059: The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to
The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2002-1185P4MEDIUMCVSS 5.0v5.0.1v5.5+1 more2002-12-11
CVE-2002-1185 [MEDIUM] CVE-2002-1185: Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when ope
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
nvd
CVE-2015-1685P4MEDIUMCVSS 4.3v112015-05-13
CVE-2015-1685 [MEDIUM] CWE-264 CVE-2015-1685: Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a
Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."
nvd
CVE-2015-2449P4MEDIUMCVSS 4.3v7v8+3 more2015-08-14
CVE-2015-2449 [MEDIUM] CWE-200 CVE-2015-2449: Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to bypass the ASLR protecti
Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."
nvd
CVE-2015-2413P4MEDIUMCVSS 4.3v6v7+4 more2015-07-14
CVE-2015-2413 [MEDIUM] CWE-200 CVE-2015-2413: Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local
Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-2410P4MEDIUMCVSS 4.3v6v7+4 more2015-07-14
CVE-2015-2410 [MEDIUM] CWE-200 CVE-2015-2410: Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local
Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted stylesheet, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-0069P4MEDIUMCVSS 4.3v10v112015-02-11
CVE-2015-0069 [MEDIUM] CWE-264 CVE-2015-0069: Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass the ASLR protection mechanis
Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
nvd
CVE-2002-0026P4HIGHCVSS 7.5v5.5v6.02002-03-08
CVE-2002-0026 [HIGH] CVE-2002-0026: Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts v
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.
nvd