cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 70 of 80
CVE-2002-0242P4HIGHCVSS 7.5≤ 6.02002-05-29
CVE-2002-0242 [HIGH] CVE-2002-0242: Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed.
nvd
CVE-2015-2421P4MEDIUMCVSS 4.3v6v7+4 more2015-07-14
CVE-2015-2421 [MEDIUM] CWE-200 CVE-2015-2421: Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mecha Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."
nvd
CVE-2014-6368P4MEDIUMCVSS 4.3v112014-12-11
CVE-2014-6368 [MEDIUM] CWE-20 CVE-2014-6368: Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
nvd
CVE-2002-0832P4HIGHCVSS 7.5v5.0v5.5+1 more2002-08-12
CVE-2002-0832 [HIGH] CVE-2002-0832: Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store information across browser sessions via the userData (storeuserData) feature.
nvd
CVE-1999-0490P4HIGHCVSS 7.5v4.0v5.01999-04-21
CVE-1999-0490 [HIGH] CVE-1999-0490: MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.
nvd
CVE-2000-0160P4HIGHCVSS 7.6v52000-02-21
CVE-2000-0160 [HIGH] CVE-2000-0160: The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attack The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
nvd
CVE-1999-0280P4HIGHCVSS 7.5v3.0v3.0.11997-04-01
CVE-1999-0280 [HIGH] CVE-1999-0280: Remote command execution in Microsoft Internet Explorer using .lnk and .url files. Remote command execution in Microsoft Internet Explorer using .lnk and .url files.
nvd
CVE-2013-1297P4MEDIUMCVSS 4.3v6v7+1 more2013-05-15
CVE-2013-1297 [MEDIUM] CWE-200 CVE-2013-1297: Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which al Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information Disclosure Vulnerability."
nvd
CVE-2015-6157P4MEDIUMCVSS 4.3v112015-12-09
CVE-2015-6157 [MEDIUM] CWE-200 CVE-2015-6157: Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2013-0015P4MEDIUMCVSS 4.3v6v7+2 more2013-02-13
CVE-2013-0015 [MEDIUM] CWE-200 CVE-2013-0015: Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS en Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS encoding, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability."
nvd
CVE-2019-1192P4MEDIUMCVSS 4.3v10v112019-08-14
CVE-2019-1192 [MEDIUM] CWE-863 CVE-2019-1192: A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker who successfully exploited the vulnerability could force the browser to
nvd
CVE-2015-2414P4MEDIUMCVSS 4.3v8v9+2 more2015-07-14
CVE-2015-2414 [MEDIUM] CWE-200 CVE-2015-2414: Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-histor Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2015-0051P4MEDIUMCVSS 4.3v82015-02-11
CVE-2015-0051 [MEDIUM] CWE-264 CVE-2015-0051: Microsoft Internet Explorer 8 allows remote attackers to bypass the ASLR protection mechanism via a Microsoft Internet Explorer 8 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
nvd
CVE-2004-1331P4LOWCVSS 2.6v6.02004-11-16
CVE-2004-1331 [LOW] CVE-2004-1331: The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
nvd
CVE-2002-0722P4HIGHCVSS 7.5v5.01v5.5+1 more2002-09-24
CVE-2002-0722 [HIGH] CVE-2002-0722: Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."
nvd
CVE-2016-7284P4MEDIUMCVSS 4.3v10v112016-12-20
CVE-2016-7284 [MEDIUM] CWE-200 CVE-2016-7284: Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from p Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-2017-0033P4MEDIUMCVSS 4.3v112017-03-17
CVE-2017-0033 [MEDIUM] CVE-2017-0033: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0069.
nvd
CVE-2007-3164P4MEDIUMCVSS 5.8v7.02007-06-11
CVE-2007-3164 [MEDIUM] CVE-2007-3164: Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, use Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the international
nvd
CVE-2017-0012P4MEDIUMCVSS 4.3v112017-03-17
CVE-2017-0012 [MEDIUM] CWE-20 CVE-2017-0012: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0033 and CVE-2017-0069.
nvd
CVE-2014-6346P4MEDIUMCVSS 4.3v8v9+2 more2014-11-11
CVE-2014-6346 [MEDIUM] CWE-200 CVE-2014-6346: Microsoft Internet Explorer 8 through 11 allows remote attackers to read content from a different (1 Microsoft Internet Explorer 8 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
nvd
Microsoft Internet Explorer vulnerabilities | cvebase