Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 74 of 80
CVE-2003-1559P4MEDIUMCVSS 5.0v5.5v62003-12-31
CVE-2003-1559 [MEDIUM] CWE-200 CVE-2003-1559: Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containi
Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
nvd
CVE-2002-1188P4MEDIUMCVSS 6.4v5.0.1v5.5+1 more2002-12-11
CVE-2002-1188 [MEDIUM] CVE-2002-1188: Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Int
Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."
nvd
CVE-2013-3192P4MEDIUMCVSS 4.3v6v7+3 more2013-08-14
CVE-2013-3192 [MEDIUM] CWE-79 CVE-2013-3192: Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote a
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."
nvd
CVE-2006-5152P4MEDIUMCVSS 6.8v6.0.29002006-10-05
CVE-2006-5152 [MEDIUM] CVE-2006-5152: Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to i
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an explicit charset, a related issue to CVE-2006-0032.
nvd
CVE-2011-1713P4MEDIUMCVSS 4.3v82011-04-15
CVE-2011-1713 [MEDIUM] CVE-2011-1713: Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain
Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. NOTE: this might overlap CVE-2011-1202.
nvd
CVE-2011-1245P4MEDIUMCVSS 4.3v6v72011-04-13
CVE-2011-1245 [MEDIUM] CWE-200 CVE-2011-1245: Microsoft Internet Explorer 6 and 7 does not properly restrict script access to content from a (1) d
Microsoft Internet Explorer 6 and 7 does not properly restrict script access to content from a (1) different domain or (2) different zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Javascript Information Disclosure Vulnerability."
nvd
CVE-2009-2954P4MEDIUMCVSS 5.0≤ 6.0.2900.2180v3.0+60 more2009-08-24
CVE-2009-2954 [MEDIUM] CVE-2009-2954: Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of s
Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.
nvd
CVE-2002-2311P4MEDIUMCVSS 6.4v5.0v5.0.1+2 more2002-12-31
CVE-2002-2311 [MEDIUM] CWE-264 CVE-2002-2311: Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this issue.
nvd
CVE-2010-3327P4MEDIUMCVSS 4.3v6v7+1 more2010-10-13
CVE-2010-3327 [MEDIUM] CWE-200 CVE-2010-3327: The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remo
The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted information by visiting a web page, aka "Anchor Element Information Disclosure Vulnerability."
nvd
CVE-1999-1087P4HIGHCVSS 7.5v4.0v4.0.11999-12-31
CVE-1999-1087 [HIGH] CVE-1999-1087: Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname inste
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
nvd
CVE-2012-0010P4MEDIUMCVSS 4.3v6v9+2 more2012-02-14
CVE-2012-0010 [MEDIUM] CWE-200 CVE-2012-0010: Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which a
Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Copy and Paste Information Disclosure Vulnerability."
nvd
CVE-2002-2435P4MEDIUMCVSS 4.3≤ 8v3.0+76 more2011-12-07
CVE-2002-2435 [MEDIUM] CWE-200 CVE-2002-2435: The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does
The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
nvd
CVE-2010-3342P4MEDIUMCVSS 4.3v6v7+1 more2010-12-16
CVE-2010-3342 [MEDIUM] CWE-200 CVE-2010-3342: Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which
Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3348.
nvd
CVE-2010-3348P4MEDIUMCVSS 4.3v6v7+1 more2010-12-16
CVE-2010-3348 [MEDIUM] CVE-2010-3348: Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which
Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3342.
nvd
CVE-2005-4844P4HIGHCVSS 7.1≤ 7.02005-12-31
CVE-2005-4844 [HIGH] CVE-2005-4844: The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explo
The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
nvd
CVE-2009-2536P4MEDIUMCVSS 4.3≤ 8v5+2 more2009-07-20
CVE-2009-2536 [MEDIUM] CVE-2009-2536: Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory
Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
nvd
CVE-2006-2384P4MEDIUMCVSS 4.3≤ 6.0v5.012006-06-13
CVE-2006-2384 [MEDIUM] CWE-200 CVE-2006-2384: Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofi
Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."
nvd
CVE-2002-0024P4HIGHCVSS 7.5v5.01v5.5+1 more2002-03-08
CVE-2002-0024 [HIGH] CVE-2002-0024: File Download box in Internet Explorer 5.01, 5.5 and 6.0 allows an attacker to use the Content-Dispo
File Download box in Internet Explorer 5.01, 5.5 and 6.0 allows an attacker to use the Content-Disposition and Content-Type HTML header fields to modify how the name of the file is displayed, which could trick a user into believing that a file is safe to download.
nvd
CVE-2018-1025P4MEDIUMCVSS 4.3v112018-05-09
CVE-2018-1025 [MEDIUM] CVE-2018-1025: An information disclosure vulnerability exists when affected Microsoft browsers improperly handle ob
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge.
nvd
CVE-2002-0815P4HIGHCVSS 7.5v6.0.29002002-08-12
CVE-2002-0815 [HIGH] CVE-2002-0815: The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Inte
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the informatio
nvd