cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 7 of 80
CVE-2011-1260P2CRITICALCVSS 9.3PoCv8v92011-06-16
CVE-2011-1260 [CRITICAL] CWE-119 CVE-2011-1260: Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability."
nvd
CVE-2011-1996P2CRITICALCVSS 9.3PoCv6v7+1 more2011-10-12
CVE-2011-1996 [CRITICAL] CVE-2011-1996: Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows rem Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
nvd
CVE-2013-3205P2CRITICALCVSS 9.3PoCv6v7+1 more2013-09-11
CVE-2013-3205 [CRITICAL] CWE-119 CVE-2013-3205: Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2017-8618P2HIGHCVSS 7.5PoCv11v10+1 more2017-07-11
CVE-2017-8618 [HIGH] CVE-2017-8618: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Internet Explorer in the way affected Microsoft scripting engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This
nvd
CVE-2018-0866P2HIGHCVSS 7.5PoCv11v10+1 more2018-02-15
CVE-2018-0866 [HIGH] CVE-2018-0866: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is
nvd
CVE-2014-1764P2CRITICALCVSS 10.0PoCv7v8+3 more2014-04-27
CVE-2014-1764 [CRITICAL] CWE-264 CVE-2014-1764: Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypas Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2013-0090P2HIGHCVSS 8.8PoCv6v7+3 more2013-03-13
CVE-2013-0090 [HIGH] CWE-399 CVE-2013-0090: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability."
nvd
CVE-2009-3672P2CRITICALCVSS 9.3PoCv6v72009-12-02
CVE-2009-3672 [CRITICAL] CWE-94 CVE-2009-3672: Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not pro Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method for the STYLE tag name, selection of the single element in the returned list, and a change to
nvd
CVE-2016-3288P2HIGHCVSS 7.5PoCv112016-08-09
CVE-2016-3288 [HIGH] CWE-119 CVE-2016-3288: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web p Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290.
nvd
CVE-2017-0202P2HIGHCVSS 7.5PoCv112017-04-12
CVE-2017-0202 [HIGH] CWE-119 CVE-2017-0202: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, a.k.a. "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2014-0282P2CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-0282 [CRITICAL] CWE-119 CVE-2014-0282: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.
nvd
CVE-2017-8594P2HIGHCVSS 7.5PoCv112017-07-11
CVE-2017-8594 [HIGH] CWE-119 CVE-2017-8594: Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability".
nvd
CVE-2018-8625P2HIGHCVSS 7.5PoCv9v10+1 more2018-12-12
CVE-2018-8625 [HIGH] CWE-416 CVE-2018-8625: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2017-11855P2HIGHCVSS 7.5PoCv11v10+1 more2017-11-15
CVE-2017-11855 [HIGH] CWE-119 CVE-2017-11855: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in
nvd
CVE-2017-11903P2HIGHCVSS 7.5PoCv11v10+1 more2017-12-12
CVE-2017-11903 [HIGH] CVE-2017-11903: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Window Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corr
nvd
CVE-2014-1770P2CRITICALCVSS 9.3PoCv6v7+4 more2014-05-22
CVE-2014-1770 [CRITICAL] CWE-399 CVE-2014-1770: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.
nvd
CVE-2018-8552P2HIGHCVSS 7.5PoCv11v10+1 more2018-11-14
CVE-2018-8552 [HIGH] CWE-119 CVE-2018-8552: An information disclosure vulnerability exists when VBScript improperly discloses the contents of it An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2013-3184P2CRITICALCVSS 9.3PoCv7v8+2 more2013-08-14
CVE-2013-3184 [CRITICAL] CWE-119 CVE-2013-3184: Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-0063P2HIGHCVSS 8.8PoCv9v10+1 more2016-02-10
CVE-2016-0063 [HIGH] CVE-2016-0063: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0067, and CVE-2016-0072.
nvd
CVE-2009-0553P2CRITICALCVSS 9.3PoCv6v72009-04-15
CVE-2009-0553 [CRITICAL] CWE-399 CVE-2009-0553: Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Unini
nvd
Microsoft Internet Explorer vulnerabilities | cvebase