cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 77 of 80
CVE-2006-3200P4MEDIUMCVSS 5.0v6.0.29002006-06-23
CVE-2006-3200 [MEDIUM] CVE-2006-3200: Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash) via an IFRAME with a src tag containing a "File://" URI followed by an 8-bit character. NOTE: some third parties were unable to verify this issue.
nvd
CVE-2008-5556P4MEDIUMCVSS 4.3v82008-12-12
CVE-2008-5556 [MEDIUM] CWE-79 CVE-2008-5556: The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviou
nvd
CVE-2006-0585P4MEDIUMCVSS 5.0≤ 6v3.0+50 more2006-02-08
CVE-2006-0585 [MEDIUM] CVE-2006-0585: jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a de jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
nvd
CVE-2018-8315P4MEDIUMCVSS 4.2v11v102018-09-13
CVE-2018-8315 [MEDIUM] CWE-200 CVE-2018-8315: An information disclosure vulnerability exists when the browser scripting engine improperly handle o An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
nvd
CVE-2006-3658P4MEDIUMCVSS 5.0v62006-07-18
CVE-2006-3658 [MEDIUM] CVE-2006-3658: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by access Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by accessing the object references of a FolderItem ActiveX object, which triggers a null dereference in the security check.
nvd
CVE-2002-0101P4MEDIUMCVSS 5.0v5.5v6.02002-03-25
CVE-2002-0101 [MEDIUM] CVE-2002-0101: Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an i Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.
nvd
CVE-2001-0332P4MEDIUMCVSS 5.0v5.01v5.52001-06-27
CVE-2001-0332 [MEDIUM] CVE-2001-0332: Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser wi Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulne
nvd
CVE-2001-0246P4MEDIUMCVSS 5.0≤ 5.5v5.012001-06-27
CVE-2001-0246 [MEDIUM] CVE-2001-0246: Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser wi Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.
nvd
CVE-2007-3576P4MEDIUMCVSS 4.3v62007-07-05
CVE-2007-3576 [MEDIUM] CVE-2007-3576: Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with th Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names with 10 or more characters, which might allow remote attackers to bypass certain XSS protection schemes
nvd
CVE-2003-0519P4MEDIUMCVSS 5.0v5.0v6.02003-08-18
CVE-2003-0519 [MEDIUM] CVE-2003-0519: Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attacke Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.
nvd
CVE-2000-0266P4LOWCVSS 2.6v5.0v5.012000-04-18
CVE-2000-0266 [LOW] CVE-2000-0266: Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malic Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.
nvd
CVE-2005-0954P4MEDIUMCVSS 5.0v6.0.29002005-05-02
CVE-2005-0954 [MEDIUM] CVE-2005-0954: Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.
nvd
CVE-2016-7199P4LOWCVSS 3.1v9v10+1 more2016-11-10
CVE-2016-7199 [LOW] CWE-200 CVE-2016-7199: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Sam Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2006-3545P4MEDIUMCVSS 5.0v7.02006-07-13
CVE-2006-3545 [MEDIUM] CVE-2006-3545: Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (applicati Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet Explorer 7.0 Beta3
nvd
CVE-1999-1473P4MEDIUMCVSS 5.0v3.0.2v4.01999-12-31
CVE-1999-1473 [MEDIUM] CVE-1999-1473: When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."
nvd
CVE-2016-7227P4LOWCVSS 3.1v9v10+1 more2016-11-10
CVE-2016-7227 [LOW] CWE-200 CVE-2016-7227: The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote at The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2007-4848P4MEDIUMCVSS 4.3v4.0v4.0.1+19 more2007-09-12
CVE-2007-4848 [MEDIUM] CVE-2007-4848: Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of loca Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.
nvd
CVE-2002-1564P4MEDIUMCVSS 5.0v5.01v5.5+1 more2003-06-09
CVE-2002-1564 [MEDIUM] CVE-2002-1564: Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information fro Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information from cookies via a cookie that contains script which is executed when a page is loaded, aka the "Script within Cookies Reading Cookies" vulnerability.
nvd
CVE-2001-0338P4MEDIUMCVSS 5.1≤ 5.5v5.012001-06-27
CVE-2001-0338 [MEDIUM] CVE-2001-0338: Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate R Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."
nvd
CVE-2001-0091P4LOWCVSS 2.6v4.0v5.0+2 more2001-02-16
CVE-2001-0091 [LOW] CVE-2001-0091: The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase