cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 80 of 80
CVE-2001-0919P4MEDIUMCVSS 5.1v5.52001-11-26
CVE-2001-0919 [MEDIUM] CVE-2001-0919: Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your ma Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.
nvd
CVE-2001-0807P4LOWCVSS 2.6v5.02001-12-06
CVE-2001-0807 [LOW] CVE-2001-0807: Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.
nvd
CVE-2001-1497P4LOWCVSS 2.1v4.0v4.0.1+2 more2001-12-31
CVE-2001-1497 [LOW] CVE-2001-1497: Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanu Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
nvd
CVE-2000-0439P4LOWCVSS 2.6v3.0v3.2+4 more2000-05-11
CVE-2000-0439 [LOW] CVE-2000-0439: Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another doma Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.
nvd
CVE-2005-2274P4LOWCVSS 2.6v6.02005-07-13
CVE-2005-2274 [LOW] CVE-2005-2274: Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
nvd
CVE-2004-2219P4LOWCVSS 2.6v5.01v5.5+1 more2004-12-31
CVE-2004-2219 [LOW] CVE-2004-2219: Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishin Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.
nvd
CVE-2004-2011P4LOWCVSS 2.6v6.0.26002004-12-31
CVE-2004-2011 [LOW] CVE-2004-2011: msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (cra msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a link, which triggers a parsing error, possibly due to missing portions of the URI.
nvd
CVE-1999-1367P4MEDIUMCVSS 4.6v5.01999-05-06
CVE-1999-1367 [MEDIUM] CVE-1999-1367: Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.
nvd
CVE-2004-2476P4LOWCVSS 2.6v6.0.28002004-12-31
CVE-2004-2476 [LOW] CVE-2004-2476: Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.
nvd
CVE-1999-0827P4LOWCVSS 2.6v3.0v3.0.2+7 more1999-11-01
CVE-1999-0827 [LOW] CVE-1999-0827: By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across differe By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
nvd
CVE-2001-1450P4LOWCVSS 2.6v5.0v5.0.1+2 more2001-05-11
CVE-2001-1450 [LOW] CVE-2001-1450: Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser c Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".
nvd
CVE-2002-1670P4MEDIUMCVSS 4.6v6.02002-12-31
CVE-2002-1670 [MEDIUM] CVE-2002-1670: Microsoft Windows XP Professional upgrade edition overwrites previously installed patches for Intern Microsoft Windows XP Professional upgrade edition overwrites previously installed patches for Internet Explorer 6.0, leaving Internet Explorer unpatched.
nvd
CVE-2008-2159P4LOWCVSS 2.1v72008-05-12
CVE-2008-2159 [LOW] CWE-200 CVE-2008-2159: Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSS Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information.
nvd
CVE-1999-1446P4LOWCVSS 2.1v3.01997-08-05
CVE-1999-1446 [LOW] CVE-1999-1446: Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located i Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase