cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 8 of 80
CVE-2018-8619P2HIGHCVSS 7.5PoCv9v10+1 more2018-12-12
CVE-2018-8619 [HIGH] CWE-269 CVE-2018-8619: A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy do A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
nvd
CVE-2010-0248P2HIGHCVSS 8.1PoCv8v8.0.6001+24 more2010-01-22
CVE-2010-0248 [HIGH] CWE-94 CVE-2010-0248: Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which all Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
nvd
CVE-2009-1547P2HIGHCVSS 8.8PoCv5.01v6+2 more2009-10-14
CVE-2009-1547 [HIGH] CWE-94 CVE-2009-1547: Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote att Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."
nvd
CVE-2016-0108P2HIGHCVSS 7.5PoCv112016-03-09
CVE-2016-0108 [HIGH] CVE-2016-0108: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0106, CVE-2016-0109, and CVE-2016-0114.
nvd
CVE-2016-1102P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-1102 [HIGH] CVE-2016-1102: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1104P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-1104 [HIGH] CVE-2016-1104: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1096P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-1096 [HIGH] CVE-2016-1096: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2013-0019P2CRITICALCVSS 9.3PoCv8v10+2 more2013-02-13
CVE-2013-0019 [CRITICAL] CWE-399 CVE-2013-0019: Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free Vulnerability."
nvd
CVE-2016-0111P2HIGHCVSS 7.5PoCv9v10+1 more2016-03-09
CVE-2016-0111 [HIGH] CVE-2016-0111: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitr Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0112, and CVE-2016-0113.
nvd
CVE-2014-1799P2CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-1799 [CRITICAL] CVE-2014-1799: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1803, and CVE-2014-2757.
nvd
CVE-2010-0027P2CRITICALCVSS 9.3PoCv8v8.0.6001+9 more2010-01-22
CVE-2010-0027 [CRITICAL] CWE-94 CVE-2010-0027: The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the She The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
nvd
CVE-2016-1105P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-1105 [HIGH] CVE-2016-1105: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4108P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-4108 [HIGH] CVE-2016-4108: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1103P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-1103 [HIGH] CVE-2016-1103: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1101P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-1101 [HIGH] CVE-2016-1101: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2013-1309P2CRITICALCVSS 9.3PoCv6v7+3 more2013-05-15
CVE-2013-1309 [CRITICAL] CVE-2013-1309: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-2551.
nvd
CVE-2016-3324P2HIGHCVSS 8.8PoCv9v10+1 more2016-09-14
CVE-2016-3324 [HIGH] CVE-2016-3324: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2016-1106P2HIGHCVSS 7.5PoCv10v112016-05-11
CVE-2016-1106 [HIGH] CVE-2016-1106: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2014-4138P2CRITICALCVSS 9.3PoCv112014-10-15
CVE-2014-4138 [CRITICAL] CVE-2014-4138: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4130 and CVE-2014-4132.
nvd
CVE-2015-2444P2CRITICALCVSS 9.3PoCv8v9+2 more2015-08-14
CVE-2015-2444 [CRITICAL] CVE-2015-2444: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase