cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 72 of 80
CVE-2007-3481P4MEDIUMCVSS 5.0v6v72007-06-28
CVE-2007-3481 [MEDIUM] CWE-119 CVE-2007-3481: Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to bypass Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute. NOTE: this issue has been disputed by other researchers, citing a variable
nvd
CVE-2017-8733P4MEDIUMCVSS 4.3v9v10+1 more2017-09-13
CVE-2017-8733 [MEDIUM] CVE-2017-8733: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into believing that the user was visiting a legitimate website, due to the way that Internet Explorer handles specific HTML c
nvd
CVE-2010-1258P4MEDIUMCVSS 4.3v6v7+1 more2010-08-11
CVE-2010-1258 [MEDIUM] CWE-200 CVE-2010-1258: Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handler Cross-Domain Vulnerability."
nvd
CVE-2010-0494P4MEDIUMCVSS 4.3v7v6+2 more2010-03-31
CVE-2010-0494 [MEDIUM] CWE-200 CVE-2010-0494: Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted re Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulner
nvd
CVE-2008-4788P4MEDIUMCVSS 5.0v62008-10-29
CVE-2008-4788 [MEDIUM] CVE-2008-4788: Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote attackers to spoof the address bar via a URL with a domain name that differs from an important domain name only in these characters, as demonstrated by using exam%A9ple.com to spoof example.com, aka MSRC ticket MSRC7900.
nvd
CVE-2003-0114P4MEDIUMCVSS 5.0v5.0.1v5.5+1 more2003-05-12
CVE-2003-0114 [MEDIUM] CVE-2003-0114: The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.
nvd
CVE-2010-3243P4MEDIUMCVSS 4.3v82010-10-13
CVE-2010-3243 [MEDIUM] CWE-79 CVE-2010-3243: Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
nvd
CVE-2002-1186P4MEDIUMCVSS 5.0v5.0.1v5.5+1 more2002-12-11
CVE-2002-1186 [MEDIUM] CVE-2002-1186: Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded char Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."
nvd
CVE-1999-1093P4MEDIUMCVSS 5.1≤ 4.0.1v4.0+1 more1999-12-31
CVE-1999-1093 [MEDIUM] CVE-1999-1093: Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
nvd
CVE-2015-6046P4MEDIUMCVSS 4.3v9v10+1 more2015-10-14
CVE-2015-6046 [MEDIUM] CWE-200 CVE-2015-6046: Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information fro Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
nvd
CVE-1999-0876P4CRITICALCVSS 10.0v4.0v4.12000-01-04
CVE-1999-0876 [CRITICAL] CWE-119 CVE-1999-0876: Buffer overflow in Internet Explorer 4.0 via EMBED tag. Buffer overflow in Internet Explorer 4.0 via EMBED tag.
nvd
CVE-2001-0712P4HIGHCVSS 7.5v5.0v5.0.1+1 more2001-10-30
CVE-2001-0712 [HIGH] CVE-2001-0712: The rendering engine in Internet Explorer determines the MIME type independently of the type that is The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.
nvd
CVE-2005-3240P4MEDIUMCVSS 5.1v5.01v5.5+1 more2005-12-31
CVE-2005-3240 [MEDIUM] CWE-362 CVE-2005-3240: Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.
nvd
CVE-2014-6323P4MEDIUMCVSS 4.3v7v8+3 more2014-11-11
CVE-2014-6323 [MEDIUM] CWE-200 CVE-2014-6323: Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard infor Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."
nvd
CVE-2002-0269P4HIGHCVSS 7.5v5.0v5.0.1+3 more2002-05-29
CVE-2002-0269 [HIGH] CVE-2002-0269: Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.
nvd
CVE-2015-6144P4MEDIUMCVSS 4.3v8v9+2 more2015-12-09
CVE-2015-6144 [MEDIUM] CWE-79 CVE-2015-6144: Microsoft Internet Explorer 8 through 11 and Microsoft Edge mishandle HTML attributes in HTTP respon Microsoft Internet Explorer 8 through 11 and Microsoft Edge mishandle HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Browser XSS Filter Bypass Vulnerability."
nvd
CVE-2011-1962P4MEDIUMCVSS 4.3v6v7+2 more2011-08-10
CVE-2011-1962 [MEDIUM] CWE-20 CVE-2011-1962: Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, wh Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers "inactive filtering," aka "Shift JIS Character Encoding Vulnerability."
nvd
CVE-2015-6138P4MEDIUMCVSS 4.3v8v9+2 more2015-12-09
CVE-2015-6138 [MEDIUM] CWE-79 CVE-2015-6138: Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerability."
nvd
CVE-2018-0932P4MEDIUMCVSS 4.3v112018-03-14
CVE-2018-0932 [MEDIUM] CWE-200 CVE-2018-0932: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows information disclosure, due to how Microsoft browsers handle objects in me
nvd
CVE-2009-2069P4MEDIUMCVSS 5.8v3.0v3.0.1+69 more2009-06-15
CVE-2009-2069 [MEDIUM] CWE-287 CVE-2009-2069: Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response pag
nvd
Microsoft Internet Explorer vulnerabilities | cvebase