Microsoft Internet Explorer vulnerabilities
1,594 known vulnerabilities affecting microsoft/internet_explorer.
Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50
Vulnerabilities
Page 78 of 80
CVE-2005-3312P4MEDIUMCVSS 4.3v6.02005-10-26
CVE-2005-3312 [MEDIUM] CVE-2005-3312: The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cros
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on the link, even though the web server response and file extension indicate that it should be treated as a di
nvd
CVE-2001-0090P4MEDIUMCVSS 5.1v5.52001-02-16
CVE-2001-0090 [MEDIUM] CVE-2001-0090: The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates witho
The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.
nvd
CVE-2016-3274P4LOWCVSS 3.1v9v10+1 more2016-07-13
CVE-2016-3274 [LOW] CWE-284 CVE-2016-3274: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct conten
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
nvd
CVE-2007-4478P4MEDIUMCVSS 4.3v6.02007-08-22
CVE-2007-4478 [MEDIUM] CVE-2007-4478: Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6.0 and 7 allows user-assist
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6.0 and 7 allows user-assisted remote attackers to inject arbitrary web script or HTML in the local zone via a URI, when the document at the associated URL is saved to a local file, which then contains the URI string along with the document's original content.
nvd
CVE-2016-3276P4LOWCVSS 3.1v112016-07-13
CVE-2016-3276 [LOW] CWE-284 CVE-2016-3276: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
nvd
CVE-2010-2118P4MEDIUMCVSS 4.3v6.0.2900.21802010-06-01
CVE-2010-2118 [MEDIUM] CWE-399 CVE-2010-2118: Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a deni
Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
nvd
CVE-2005-4810P4MEDIUMCVSS 5.0v7.02005-12-31
CVE-2005-4810 [MEDIUM] CVE-2005-4810: Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of servi
Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
nvd
CVE-2000-0162P4MEDIUMCVSS 5.1v4.02000-02-18
CVE-2000-0162 [MEDIUM] CVE-2000-0162: The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
nvd
CVE-2010-2119P4MEDIUMCVSS 4.3v6.0.2900.21802010-06-01
CVE-2010-2119 [MEDIUM] CWE-399 CVE-2010-2119: Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (reso
Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid nntp:// URIs.
nvd
CVE-2009-0072P4MEDIUMCVSS 4.3v6v7+1 more2009-01-08
CVE-2009-0072 [MEDIUM] CVE-2009-0072: Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of servi
Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.
nvd
CVE-2016-3291P4LOWCVSS 2.4v112016-09-14
CVE-2016-3291 [LOW] CWE-200 CVE-2016-3291: Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remo
Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-2000-0767P4LOWCVSS 2.6v4.0v5.0+2 more2000-10-20
CVE-2000-0767 [LOW] CVE-2000-0767: The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file
The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.
nvd
CVE-2012-6502P4LOWCVSS 2.6v6v7+3 more2013-01-22
CVE-2012-6502 [LOW] CWE-200 CVE-2012-6502: Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about
Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a local file via a \\127.0.0.1\C$\ sequence.
nvd
CVE-1999-1128P4MEDIUMCVSS 5.1v3.0.11997-03-01
CVE-1999-1128 [MEDIUM] CVE-1999-1128: Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands
Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.
nvd
CVE-2001-1539P4MEDIUMCVSS 5.0v6.0.29002001-12-31
CVE-2001-1539 [MEDIUM] CWE-119 CVE-2001-1539: Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem.
nvd
CVE-2016-7239P4LOWCVSS 3.1v9v10+1 more2016-11-10
CVE-2016-7239 [LOW] CWE-79 CVE-2016-7239: The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge all
The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
nvd
CVE-1999-1370P4HIGHCVSS 7.2v5.01999-03-23
CVE-1999-1370 [HIGH] CVE-1999-1370: The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.
nvd
CVE-2004-0979P4MEDIUMCVSS 4.6v6.02004-12-31
CVE-2004-0979 [MEDIUM] CVE-2004-0979: Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files"
Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configuration.
nvd
CVE-2005-2304P4MEDIUMCVSS 5.0v6.02005-07-19
CVE-2005-2304 [MEDIUM] CVE-2005-2304: Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of s
Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.
nvd
CVE-2004-2307P4MEDIUMCVSS 5.0v6.0.26002004-12-31
CVE-2004-2307 [MEDIUM] CVE-2004-2307: Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of serv
Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A.
nvd