cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 79 of 80
CVE-2003-1105P4LOWCVSS 2.6v5.01v5.5+1 more2003-12-31
CVE-2003-1105 [LOW] CVE-2003-1105: Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.
nvd
CVE-2007-4227P4MEDIUMCVSS 4.3v6.0v72007-08-08
CVE-2007-4227 [MEDIUM] CVE-2007-4227: Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain JPG file, as demonstrated by something.jpg. NOTE: this issue might be related to CVE-2007-3958.
nvd
CVE-2006-0799P4MEDIUMCVSS 4.0v6.0.29002006-02-19
CVE-2006-0799 [MEDIUM] CVE-2006-0799: Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL. NOTE: this issue is very similar to CVE
nvd
CVE-2006-3659P4MEDIUMCVSS 5.0v62006-07-18
CVE-2006-3659 [MEDIUM] CVE-2006-3659: Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by settin Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the location or URL property of a MHTMLFile ActiveX object.
nvd
CVE-2002-1824P4MEDIUMCVSS 5.0v6.02002-12-31
CVE-2002-1824 [MEDIUM] CVE-2002-1824: Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack. NOTE: it is not clear whether this poses a vulnerability.
nvd
CVE-2002-0136P4MEDIUMCVSS 5.0v5.52002-03-25
CVE-2002-0136 [MEDIUM] CVE-2002-0136: Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service ( Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript.
nvd
CVE-1999-1447P4MEDIUMCVSS 5.0v4.01998-07-28
CVE-1999-1447 [MEDIUM] CVE-1999-1447: Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code tha Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.
nvd
CVE-2004-1922P4LOWCVSS 2.6v5.5v6.02004-04-11
CVE-2004-1922 [LOW] CVE-2004-1922: Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.
nvd
CVE-1999-0031P4LOWCVSS 2.6v3.0v4.01997-07-08
CVE-1999-0031 [LOW] CVE-1999-0031: JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.
nvd
CVE-2001-0092P4LOWCVSS 2.6v5.0v5.01+1 more2001-02-16
CVE-2001-0092 [LOW] CVE-2001-0092: A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame withi A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.
nvd
CVE-1999-0871P4LOWCVSS 2.6v4.0v4.0.11998-09-04
CVE-1999-0871 [LOW] CVE-1999-0871: Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.
nvd
CVE-2010-0808P4LOWCVSS 2.6v6v72010-10-13
CVE-2010-0808 [LOW] CWE-200 CVE-2010-0808: Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, aka "AutoComplete Information Disclosure Vulnerability."
nvd
CVE-2000-0503P4LOWCVSS 2.6v4.0v5.0+2 more2000-06-06
CVE-2000-0503 [LOW] CVE-2000-0503: The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate t The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.
nvd
CVE-2002-1984P4MEDIUMCVSS 5.0v5.0.1v5.5+1 more2002-12-31
CVE-2002-1984 [MEDIUM] CVE-2002-1984: Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
nvd
CVE-2001-1219P4MEDIUMCVSS 5.0v5.5v6.02001-12-20
CVE-2001-1219 [MEDIUM] CVE-2001-1219: Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.
nvd
CVE-2007-2161P4MEDIUMCVSS 4.3v7.02007-04-22
CVE-2007-2161 [MEDIUM] CVE-2007-2161: Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) vi Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.
nvd
CVE-2018-0942P4LOWCVSS 2.6v112018-03-14
CVE-2018-0942 [LOW] CVE-2018-0942: Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Wi Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow elevation of privilege, due to how Internet Explorer handles zone and integrity settings, aka "Internet Explorer Elevation of Privilege Vulnerability".
nvd
CVE-2000-0519P4LOWCVSS 2.6v4.02000-06-05
CVE-2000-0519 [LOW] CVE-2000-0519: Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establish Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
nvd
CVE-2000-0518P4LOWCVSS 2.6v4.02000-06-05
CVE-2000-0518 [LOW] CVE-2000-0518: Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a conne Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.
nvd
CVE-2000-0768P4LOWCVSS 2.6v4.0v5.01+1 more2000-10-20
CVE-2000-0768 [LOW] CVE-2000-0768: A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase