cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 73 of 80
CVE-2018-0847P4MEDIUMCVSS 4.3v112018-02-15
CVE-2018-0847 [MEDIUM] CWE-787 CVE-2018-0847: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow information disclosure, due to how Internet Explorer handles objects in memory, aka "Internet Explorer Information Disclosure Vulnerability".
nvd
CVE-2017-11790P4MEDIUMCVSS 4.3v9v10+1 more2017-10-13
CVE-2017-11790 [MEDIUM] CWE-200 CVE-2017-11790: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handles objects in memory, aka "Interne
nvd
CVE-2018-0989P4MEDIUMCVSS 4.3v10v11+1 more2018-04-12
CVE-2018-0989 [MEDIUM] CVE-2018-0989: An information disclosure vulnerability exists in the way that the scripting engine handles objects An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-1000.
nvd
CVE-2018-0929P4MEDIUMCVSS 4.3v9v10+1 more2018-03-14
CVE-2018-0929 [MEDIUM] CWE-200 CVE-2018-0929: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow information disclosure, due to how Internet Explorer handles objects in memory, aka "Internet Explorer Information Disclosure Vulnerability"
nvd
CVE-2018-0927P4MEDIUMCVSS 4.3v10v112018-03-14
CVE-2018-0927 [MEDIUM] CWE-200 CVE-2018-0927: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows information disclosure, due to how Microsoft browsers handle objects in me
nvd
CVE-2008-1368P4MEDIUMCVSS 4.3v5v62008-03-18
CVE-2008-1368 [MEDIUM] CVE-2008-1368: CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execu CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an authenticated FTP connection established earlier in the same browser session, as demonstrated using a
nvd
CVE-2009-2576P4MEDIUMCVSS 5.0≤ 6.0.2900.2180v3.0+54 more2009-07-22
CVE-2009-2576 [MEDIUM] CVE-2009-2576: Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of s Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
nvd
CVE-2019-0762P4MEDIUMCVSS 4.3v112019-04-09
CVE-2019-0762 [MEDIUM] CWE-863 CVE-2019-0762: A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.
nvd
CVE-2002-0691P4HIGHCVSS 7.5v5.01v5.52002-09-24
CVE-2002-0691 [HIGH] CVE-2002-0691: Microsoft Internet Explorer 5.01 and 5.5 allows remote attackers to execute scripts in the Local Com Microsoft Internet Explorer 5.01 and 5.5 allows remote attackers to execute scripts in the Local Computer zone via a URL that references a local HTML resource file, a variant of "Cross-Site Scripting in Local HTML Resource" as identified by CAN-2002-0189.
nvd
CVE-2019-1220P4MEDIUMCVSS 4.3v9v10+1 more2019-09-11
CVE-2019-1220 [MEDIUM] CWE-425 CVE-2019-1220: A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'.
nvd
CVE-2003-0116P4MEDIUMCVSS 5.0v5.0.1v5.5+1 more2003-05-12
CVE-2003-0116 [MEDIUM] CVE-2003-0116: Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet inpu Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."
nvd
CVE-2008-4381P4MEDIUMCVSS 5.0v5v6+1 more2008-10-02
CVE-2008-4381 [MEDIUM] CWE-399 CVE-2008-4381: Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application cras Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
nvd
CVE-1999-0537P4HIGHCVSS 7.5v6.0.29001998-04-01
CVE-1999-0537 [HIGH] CVE-1999-0537: A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.
nvd
CVE-2012-1882P4MEDIUMCVSS 4.3v7v8+2 more2012-06-12
CVE-2012-1882 [MEDIUM] CWE-200 CVE-2012-1882: Microsoft Internet Explorer 6 through 9 does not block cross-domain scrolling events, which allows r Microsoft Internet Explorer 6 through 9 does not block cross-domain scrolling events, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Scrolling Events Information Disclosure Vulnerability."
nvd
CVE-1999-0670P4MEDIUMCVSS 4.0v4.0v5.01999-09-01
CVE-1999-0670 [MEDIUM] CVE-1999-0670: Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.
nvd
CVE-2011-3404P4MEDIUMCVSS 4.3v6v7+2 more2011-12-14
CVE-2011-3404 [MEDIUM] CWE-200 CVE-2011-3404: Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Content-Disposition Information Disclosure Vulnerability."
nvd
CVE-2004-0719P4HIGHCVSS 7.5v5.0.1v5.5+1 more2004-07-27
CVE-2004-0719 [HIGH] CVE-2004-0719: Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, doe Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
nvd
CVE-2015-2398P4MEDIUMCVSS 4.3v8v9+2 more2015-07-14
CVE-2015-2398 [MEDIUM] CWE-79 CVE-2015-2398: Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a craf Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability."
nvd
CVE-2009-3267P4MEDIUMCVSS 5.0≥ 6.0, ≤ 6.00.2900.2180≥ 7.0, ≤ 7.0.6000.167112009-09-18
CVE-2009-3267 [MEDIUM] CVE-2009-3267: Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.
nvd
CVE-2001-0874P4MEDIUMCVSS 5.0v5.5v6.02001-12-13
CVE-2001-0874 [MEDIUM] CVE-2001-0874: Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes info Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes information from a frame in the client's domain to a frame in the web site's domain, a variant of the "Frame Domain Verification" vulnerability.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase