cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 71 of 80
CVE-2017-11848P4MEDIUMCVSS 4.3v112017-11-15
CVE-2017-11848 [MEDIUM] CWE-200 CVE-2017-11848: Internet Explorer in Microsoft Microsoft Windows 7 SP1, Windows Server 2008 SP2, Windows 8.1 and Win Internet Explorer in Microsoft Microsoft Windows 7 SP1, Windows Server 2008 SP2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to detect the navigation of the user leaving a maliciously crafted page, due to how page content
nvd
CVE-2020-1315P4MEDIUMCVSS 5.3v11v92020-06-09
CVE-2020-1315 [MEDIUM] CVE-2020-1315: An information disclosure vulnerability exists when Internet Explorer improperly handles objects in An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
nvd
CVE-2011-1960P4MEDIUMCVSS 4.3v6v7+2 more2011-08-10
CVE-2011-1960 [MEDIUM] CWE-668 CVE-2011-1960: Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Event Handlers Information Disclosure Vulnerability."
nvd
CVE-2001-0339P4HIGHCVSS 7.5≤ 5.52001-06-27
CVE-2001-0339 [HIGH] CVE-2001-0339: Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that i Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."
nvd
CVE-2017-0154P4MEDIUMCVSS 4.4v112017-03-17
CVE-2017-0154 [MEDIUM] CWE-74 CVE-2017-0154: Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforc Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2004-1376P4MEDIUMCVSS 5.0v5.01v5.5+1 more2004-12-30
CVE-2004-1376 [MEDIUM] CVE-2004-1376: Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote ma Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.
nvd
CVE-2016-0077P4MEDIUMCVSS 4.3v9v10+1 more2016-02-10
CVE-2016-0077 [MEDIUM] CWE-19 CVE-2016-0077: Microsoft Internet Explorer 9 through 11 and Microsoft Edge misparse HTTP responses, which allows re Microsoft Internet Explorer 9 through 11 and Microsoft Edge misparse HTTP responses, which allows remote attackers to spoof web sites via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
nvd
CVE-2017-8736P4MEDIUMCVSS 4.3v112017-09-13
CVE-2017-8736 [MEDIUM] CWE-200 CVE-2017-8736: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to obtain specific information used in the parent domain, due to Microsoft browser parent domain verif
nvd
CVE-2001-0724P4HIGHCVSS 7.5v5.52001-11-14
CVE-2001-0724 [HIGH] CVE-2001-0724: Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs tha Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing Vulnerability variant" of CVE-2001-0664.
nvd
CVE-2013-1450P4MEDIUMCVSS 4.0v8v92013-01-29
CVE-2013-1450 [MEDIUM] CWE-16 CVE-2013-1450: Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy addres Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS reque
nvd
CVE-2010-1127P4MEDIUMCVSS 5.0v6.0v6.00.2462.0000+20 more2010-03-26
CVE-2010-1127 [MEDIUM] CVE-2010-1127: Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createE
nvd
CVE-2002-0077P4HIGHCVSS 7.5v5.0.1v5.5+1 more2002-01-13
CVE-2002-0077 [HIGH] CVE-2002-0077: Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codeba Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.
nvd
CVE-2011-2382P4MEDIUMCVSS 4.3≤ 8v3.0+75 more2011-06-03
CVE-2011-2382 [MEDIUM] CWE-20 CVE-2011-2382: Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.
nvd
CVE-1999-0468P4HIGHCVSS 8.2v5.01999-04-09
CVE-1999-0468 [HIGH] CWE-200 CVE-1999-0468: Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system usi Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.
nvd
CVE-1999-1472P4MEDIUMCVSS 5.0v4.01999-12-31
CVE-1999-1472 [MEDIUM] CVE-1999-1472: Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's ma Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.
nvd
CVE-2011-1992P4MEDIUMCVSS 4.3v82011-12-14
CVE-2011-1992 [MEDIUM] CWE-79 CVE-2011-1992: The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to read content from a diffe The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to read content from a different (1) domain or (2) zone via a "trial and error" attack, aka "XSS Filter Information Disclosure Vulnerability."
nvd
CVE-2009-2057P4MEDIUMCVSS 5.8v3.0v3.0.1+69 more2009-06-15
CVE-2009-2057 [MEDIUM] CWE-287 CVE-2009-2057: Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a documen Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
nvd
CVE-2013-5046P4MEDIUMCVSS 6.2v7v8+3 more2013-12-11
CVE-2013-5046 [MEDIUM] CWE-20 CVE-2013-5046: Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."
nvd
CVE-2018-0987P4MEDIUMCVSS 4.3v10v11+1 more2018-04-12
CVE-2018-0987 [MEDIUM] CVE-2018-0987: An information disclosure vulnerability exists when the scripting engine does not properly handle ob An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0989, CVE-2018-1000.
nvd
CVE-2008-1545P4MEDIUMCVSS 4.3v7.0v7.0.5730.112008-03-28
CVE-2008-1545 [MEDIUM] CWE-20 CVE-2008-1545: The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not r The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorre
nvd
Microsoft Internet Explorer vulnerabilities | cvebase