Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 68 of 80
CVE-2015-6052P4MEDIUMCVSS 4.3v8v9+2 more2015-10-14
CVE-2015-6052 [MEDIUM] CWE-200 CVE-2015-6052: The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Expl
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript ASLR Bypass."
nvd
CVE-2015-6051P4MEDIUMCVSS 4.3v10v112015-10-14
CVE-2015-6051 [MEDIUM] CVE-2015-6051: Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web s
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2006-3640P4MEDIUMCVSS 5.0v5.012006-08-09
CVE-2006-3640 [MEDIUM] CVE-2006-3640: Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between p
Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited web pages in other domains or zones, aka "Window Location Information Disclosure Vulnerability."
nvd
CVE-2005-2829P4MEDIUMCVSS 5.1v5.0.1v5.5+1 more2005-12-14
CVE-2005-2829 [MEDIUM] CVE-2005-2829: Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers
Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Downloa
nvd
CVE-2015-1765P4MEDIUMCVSS 4.3v9v10+1 more2015-06-10
CVE-2015-1765 [MEDIUM] CWE-200 CVE-2015-1765: Microsoft Internet Explorer 9 through 11 allows remote attackers to read the browser history via a c
Microsoft Internet Explorer 9 through 11 allows remote attackers to read the browser history via a crafted web site.
nvd
CVE-2002-0052P4MEDIUMCVSS 5.0v5.0.1v5.01+2 more2002-03-08
CVE-2002-0052 [MEDIUM] CVE-2002-0052: Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security check
Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.
nvd
CVE-2005-4843P4HIGHCVSS 7.8v7.02005-12-31
CVE-2005-4843 [HIGH] CVE-2005-4843: The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explor
The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
nvd
CVE-2011-1244P4MEDIUMCVSS 5.8v6v7+1 more2011-04-13
CVE-2011-1244 [MEDIUM] CWE-1021 CVE-2011-1244: Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content acc
Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web site, aka "Frame Tag Information Disclosure Vulnerability."
nvd
CVE-2002-0188P4HIGHCVSS 7.5v5.01v6.02002-05-29
CVE-2002-0188 [HIGH] CVE-2002-0188: Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malfor
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the second variant of the "Content Disposition" vulnerab
nvd
CVE-2004-0845P4MEDIUMCVSS 6.4v5.01v5.52004-11-03
CVE-2004-0845 [MEDIUM] CVE-2004-0845: Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attacker
Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
nvd
CVE-2004-0866P4HIGHCVSS 7.5v6.02004-09-16
CVE-2004-0866 [HIGH] CVE-2004-0866: Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such a
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-2014-0293P4MEDIUMCVSS 4.3v9v10+1 more2014-02-12
CVE-2014-0293 [MEDIUM] CWE-200 CVE-2014-0293: Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1
Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
nvd
CVE-2011-4689P4MEDIUMCVSS 5.0v6v7+2 more2011-12-07
CVE-2011-4689 [MEDIUM] CWE-264 CVE-2011-4689: Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Ori
Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.
nvd
CVE-2015-2489P4MEDIUMCVSS 4.3v112015-09-09
CVE-2015-2489 [MEDIUM] CWE-264 CVE-2015-2489: Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, as
Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Elevation of Privilege Vulnerability."
nvd
CVE-2009-2064P4MEDIUMCVSS 6.8≤ 8v5+6 more2009-06-15
CVE-2009-2064 [MEDIUM] CWE-287 CVE-2009-2064: Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages
Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to
nvd
CVE-2015-0070P4MEDIUMCVSS 4.3v6v7+4 more2015-02-11
CVE-2015-0070 [MEDIUM] CWE-200 CVE-2015-0070: Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1
Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
nvd
CVE-1999-0967P4CRITICALCVSS 10.0v4.01997-11-01
CVE-1999-0967 [CRITICAL] CVE-1999-0967: Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
nvd
CVE-2015-1661P4MEDIUMCVSS 4.3v6v7+4 more2015-04-14
CVE-2015-1661 [MEDIUM] CWE-264 CVE-2015-1661: Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mecha
Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
nvd
CVE-2010-5071P4MEDIUMCVSS 5.0≤ 8v3.0+76 more2011-12-07
CVE-2010-5071 [MEDIUM] CWE-264 CVE-2010-5071: The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restr
The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
nvd
CVE-2018-8470P4MEDIUMCVSS 6.1v112018-09-13
CVE-2018-8470 [MEDIUM] CWE-79 CVE-2018-8470: A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled t
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
nvd