Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 75 of 80
CVE-2018-8452P4MEDIUMCVSS 4.3v112018-09-13
CVE-2018-8452 [MEDIUM] CWE-200 CVE-2018-8452: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.
nvd
CVE-2020-0706P4MEDIUMCVSS 4.3v10v112020-02-11
CVE-2020-0706 [MEDIUM] CVE-2020-0706: An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cr
An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'.
nvd
CVE-2020-1432P4MEDIUMCVSS 4.3v112020-07-14
CVE-2020-1432 [MEDIUM] CVE-2020-1432: An information disclosure vulnerability exists when Skype for Business is accessed via Internet Expl
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
nvd
CVE-2005-4841P4HIGHCVSS 7.1v7.02005-12-31
CVE-2005-4841 [HIGH] CVE-2005-4841: The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Expl
The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
nvd
CVE-2005-4842P4HIGHCVSS 7.1v7.02005-12-31
CVE-2005-4842 [HIGH] CVE-2005-4842: The System Monitor Source Properties control allows remote attackers to cause a denial of service (I
The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
nvd
CVE-2017-0231P4MEDIUMCVSS 4.3v112017-05-12
CVE-2017-0231 [MEDIUM] CWE-20 CVE-2017-0231: A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Br
A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability."
nvd
CVE-2000-0201P4MEDIUMCVSS 5.1v5.0v5.012000-03-01
CVE-2000-0201 [MEDIUM] CVE-2000-0201: The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be
The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.
nvd
CVE-2011-1258P4MEDIUMCVSS 4.3v6v7+1 more2011-06-16
CVE-2011-1258 [MEDIUM] CWE-668 CVE-2011-1258: Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-ass
Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a drag-and-drop operation, aka "Drag and Drop Information Disclosure Vulnerability."
nvd
CVE-2010-1489P4MEDIUMCVSS 4.3v82010-04-20
CVE-2010-1489 [MEDIUM] CVE-2010-1489: The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT t
The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.
nvd
CVE-2008-5554P4MEDIUMCVSS 4.3v82008-12-12
CVE-2008-5554 [MEDIUM] CWE-79 CVE-2008-5554: The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly s
nvd
CVE-1999-0870P4LOWCVSS 2.6v4.0.11998-10-01
CVE-1999-0870 [LOW] CVE-1999-0870: Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into t
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
nvd
CVE-1999-0917P4MEDIUMCVSS 5.1v4.0v5.01999-05-27
CVE-1999-0917 [MEDIUM] CVE-1999-0917: The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary fi
The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.
nvd
CVE-2002-2125P4MEDIUMCVSS 6.4v6.0.2600v6.0.2800.11062002-12-31
CVE-2002-2125 [MEDIUM] CVE-2002-2125: Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is
Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.
nvd
CVE-1999-0354P4HIGHCVSS 7.5v4.0v5.01999-11-01
CVE-1999-0354 [HIGH] CVE-1999-0354: Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.
nvd
CVE-1999-0469P4MEDIUMCVSS 5.0v5.01999-04-01
CVE-1999-0469 [MEDIUM] CVE-1999-0469: Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web s
Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.
nvd
CVE-2005-0500P4MEDIUMCVSS 5.0v6.02005-05-02
CVE-2005-0500 [MEDIUM] CVE-2005-0500: Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in
Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.
nvd
CVE-2006-3657P4MEDIUMCVSS 5.0v62006-07-18
CVE-2006-3657 [MEDIUM] CVE-2006-3657: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow e
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow exception) via a DXImageTransform.Microsoft.Gradient ActiveX object with a long (1) StartColorStr or (2) EndColorStr property.
nvd
CVE-2001-0723P4MEDIUMCVSS 6.4v5.5v6.02001-11-14
CVE-2001-0723 [MEDIUM] CVE-2001-0723: Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."
nvd
CVE-2009-3003P4MEDIUMCVSS 4.3v6v7+1 more2009-08-28
CVE-2009-3003 [MEDIUM] CVE-2009-3003: Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window
Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.
nvd
CVE-2008-4127P4MEDIUMCVSS 4.3v7.0.5730v8.0.60012008-09-18
CVE-2008-4127 [MEDIUM] CWE-399 CVE-2008-4127: Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allo
Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.
nvd