cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 76 of 80
CVE-2007-5277P4MEDIUMCVSS 4.3v6.02007-10-08
CVE-2007-5277 [MEDIUM] CVE-2007-5277: Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, wh Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80, a different issue than CVE-2006-4560.
nvd
CVE-1999-0858P4MEDIUMCVSS 5.0v5.01999-12-02
CVE-1999-0858 [MEDIUM] CWE-16 CVE-1999-0858: Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a mal Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.
nvd
CVE-2009-4074P4MEDIUMCVSS 4.3v82009-11-25
CVE-2009-4074 [MEDIUM] CVE-2009-4074: The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-ch The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability.
nvd
CVE-2019-0654P4MEDIUMCVSS 4.3v10v11+1 more2019-03-05
CVE-2019-0654 [MEDIUM] CVE-2019-0654: A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka ' A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'.
nvd
CVE-2009-3943P4MEDIUMCVSS 5.0≥ 6, ≤ 6.0.2900.2180≥ 7.0, ≤ 7.0.6000.167112009-11-16
CVE-2009-3943 [MEDIUM] CVE-2009-3943: Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attac Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property.
nvd
CVE-2019-1081P4MEDIUMCVSS 4.2v9v10+1 more2019-06-12
CVE-2019-1081 [MEDIUM] CWE-200 CVE-2019-1081: An information disclosure vulnerability exists when affected Microsoft browsers improperly handle ob An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website that is used to a
nvd
CVE-2008-5555P4MEDIUMCVSS 4.3v82008-12-12
CVE-2008-5555 [MEDIUM] CWE-79 CVE-2008-5555: Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (X
nvd
CVE-2007-3497P4MEDIUMCVSS 5.0v7.02007-06-29
CVE-2007-3497 [MEDIUM] CVE-2007-3497: Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via the history.length JavaScript variable.
nvd
CVE-2008-5553P4MEDIUMCVSS 4.3v82008-12-12
CVE-2008-5553 [MEDIUM] CWE-79 CVE-2008-5553: The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not
nvd
CVE-2011-1246P4MEDIUMCVSS 4.3v82011-06-16
CVE-2011-1246 [MEDIUM] CWE-200 CVE-2011-1246: Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which all Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."
nvd
CVE-2002-0500P4MEDIUMCVSS 5.0v5.0v5.0.1+2 more2002-08-12
CVE-2002-0500 [MEDIUM] CVE-2002-0500: Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.
nvd
CVE-2002-0025P4MEDIUMCVSS 5.0v5.01v5.5+1 more2002-03-08
CVE-2002-0025 [MEDIUM] CVE-2002-0025: Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, whi Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, which allows remote attackers to modify which application is used to process a document.
nvd
CVE-2001-0904P4MEDIUMCVSS 5.0v5.5v6.02001-11-20
CVE-2001-0904 [MEDIUM] CVE-2001-0904: Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgen Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.
nvd
CVE-2006-7029P4MEDIUMCVSS 5.0≤ 6.02007-02-23
CVE-2006-7029 [MEDIUM] CVE-2006-7029: Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service ( Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a frameset with only one frame that calls resizeTo with certain arguments. NOTE: this issue might be related to CVE-2006-3637.
nvd
CVE-2019-1357P4MEDIUMCVSS 4.3v10v112019-10-10
CVE-2019-1357 [MEDIUM] CVE-2019-1357: A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Micr A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
nvd
CVE-2019-0608P4MEDIUMCVSS 4.3v10v11+1 more2019-10-10
CVE-2019-0608 [MEDIUM] CWE-290 CVE-2019-0608: A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'M A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.
nvd
CVE-2002-1671P4MEDIUMCVSS 5.0v5.0v5.01+2 more2002-12-31
CVE-2002-1671 [MEDIUM] CVE-2002-1671: Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of th Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object.
nvd
CVE-2004-0284P4MEDIUMCVSS 5.0v6.02004-11-23
CVE-2004-0284 [MEDIUM] CVE-2004-0284: Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a de Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
nvd
CVE-2010-1991P4MEDIUMCVSS 5.0v6.0.2900.2180v7+1 more2010-05-20
CVE-2010-1991 [MEDIUM] CWE-399 CVE-2010-1991: Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situ Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
nvd
CVE-2008-5552P4MEDIUMCVSS 4.3v82008-12-12
CVE-2008-5552 [MEDIUM] CWE-79 CVE-2008-5552: The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS p The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not a
nvd
Microsoft Internet Explorer vulnerabilities | cvebase