Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 69 of 80
CVE-1999-0488P4HIGHCVSS 7.5v4.0v4.0.1+1 more1999-04-21
CVE-1999-0488 [HIGH] CVE-1999-0488: Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different se
Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.
nvd
CVE-2015-2445P4MEDIUMCVSS 4.3v102015-08-14
CVE-2015-2445 [MEDIUM] CWE-200 CVE-2015-2445: Microsoft Internet Explorer 10 allows remote attackers to bypass the ASLR protection mechanism via a
Microsoft Internet Explorer 10 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."
nvd
CVE-2007-1091P4MEDIUMCVSS 6.8v6.02007-02-26
CVE-2007-1091 [MEDIUM] CVE-2007-1091: Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof th
Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
nvd
CVE-2014-6365P4MEDIUMCVSS 4.3v8v9+2 more2014-12-11
CVE-2014-6365 [MEDIUM] CVE-2014-6365: Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a craf
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6328.
nvd
CVE-2015-2402P4MEDIUMCVSS 4.3v7v8+3 more2015-07-14
CVE-2015-2402 [MEDIUM] CWE-264 CVE-2015-2402: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-1999-0802P4HIGHCVSS 7.6v5.01999-05-27
CVE-1999-0802 [HIGH] CWE-119 CVE-1999-0802: Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed F
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.
nvd
CVE-2012-1873P4MEDIUMCVSS 4.3v7v8+1 more2012-06-12
CVE-2012-1873 [MEDIUM] CWE-200 CVE-2012-1873: Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which a
Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which allows remote attackers to obtain sensitive information from process memory via a crafted HTML document, aka "Null Byte Information Disclosure Vulnerability."
nvd
CVE-2012-1872P4MEDIUMCVSS 6.1v6v7+2 more2012-06-12
CVE-2012-1872 [MEDIUM] CWE-79 CVE-2012-1872: Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote at
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."
nvd
CVE-2000-0662P4MEDIUMCVSS 5.0v5.01v5.52000-07-14
CVE-2000-0662 [MEDIUM] CVE-2000-0662: Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redir
Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).
nvd
CVE-2015-1627P4MEDIUMCVSS 4.3v7v8+3 more2015-03-11
CVE-2015-1627 [MEDIUM] CWE-264 CVE-2015-1627: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2014-6349P4MEDIUMCVSS 4.3v10v112014-11-11
CVE-2014-6349 [MEDIUM] CWE-264 CVE-2014-6349: Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web s
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6350.
nvd
CVE-2015-0054P4MEDIUMCVSS 4.3v10v112015-02-11
CVE-2015-0054 [MEDIUM] CWE-264 CVE-2015-0054: Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted we
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2015-0055P4MEDIUMCVSS 4.3v10v112015-02-11
CVE-2015-0055 [MEDIUM] CWE-264 CVE-2015-0055: Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web s
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2013-3909P4MEDIUMCVSS 4.3v6v7+1 more2013-11-13
CVE-2013-3909 [MEDIUM] CWE-200 CVE-2013-3909: Microsoft Internet Explorer 6 through 8 allows remote attackers to read content from a different (1)
Microsoft Internet Explorer 6 through 8 allows remote attackers to read content from a different (1) domain or (2) zone via crafted characters in Cascading Style Sheets (CSS) token sequences, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-6059P4MEDIUMCVSS 4.3v8v9+2 more2015-10-14
CVE-2015-6059 [MEDIUM] CWE-200 CVE-2015-6059: The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Expl
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."
nvd
CVE-2015-1729P4MEDIUMCVSS 4.3v9v10+1 more2015-07-14
CVE-2015-1729 [MEDIUM] CWE-200 CVE-2015-1729: Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1
Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2011-2383P4MEDIUMCVSS 4.3≤ 9v3.0+5 more2011-06-03
CVE-2011-2383 [MEDIUM] CWE-20 CVE-2011-2383: Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop action
Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL that redirects to a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue
nvd
CVE-2006-2056P4MEDIUMCVSS 5.0v6.02006-04-26
CVE-2006-2056 [MEDIUM] CWE-88 CVE-2006-2056: Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remo
Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether
nvd
CVE-2000-0982P4HIGHCVSS 7.5v4.0v4.0.1+3 more2000-12-19
CVE-2000-0982 [HIGH] CVE-2000-0982: Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure page
Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.
nvd
CVE-2009-5159P4MEDIUMCVSS 6.1v52020-03-13
CVE-2009-5159 [MEDIUM] CWE-79 CVE-2009-5159: Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allo
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
nvd