cbcvebase.

Microsoft Internet Explorer vulnerabilities

1,594 known vulnerabilities affecting microsoft/internet_explorer.

Total CVEs
1,594
CISA KEV
42
actively exploited
Public exploits
364
Exploited in wild
91
Severity breakdown
CRITICAL689HIGH451MEDIUM404LOW50

Vulnerabilities

Page 9 of 80
CVE-2015-0050P2CRITICALCVSS 9.3PoCv8v92015-02-11
CVE-2015-0050 [CRITICAL] CVE-2015-0050: Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a den Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0044.
nvd
CVE-2013-1306P2CRITICALCVSS 9.3PoCv92013-05-15
CVE-2013-1306 [CRITICAL] CWE-416 CVE-2013-1306: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1313.
nvd
CVE-2014-1785P2CRITICALCVSS 9.3PoCv112014-06-11
CVE-2014-1785 [CRITICAL] CVE-2014-1785: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014
nvd
CVE-2014-1779P2CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-1779 [CRITICAL] CVE-2014-1779: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.
nvd
CVE-2014-2757P2CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-2757 [CRITICAL] CVE-2014-2757: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-1803.
nvd
CVE-2014-1775P2CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-1775 [CRITICAL] CVE-2014-1775: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.
nvd
CVE-2014-1803P2CRITICALCVSS 9.3PoCv6v7+4 more2014-06-11
CVE-2014-1803 [CRITICAL] CVE-2014-1803: Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-2757.
nvd
CVE-2014-6363P2CRITICALCVSS 9.3PoCv6v7+4 more2014-12-11
CVE-2014-6363 [CRITICAL] CWE-399 CVE-2014-6363: vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."
nvd
CVE-2014-1766P2CRITICALCVSS 9.3PoCv9v10+1 more2014-04-27
CVE-2014-1766 [CRITICAL] CWE-119 CVE-2014-1766: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet
nvd
CVE-2013-1311P2CRITICALCVSS 9.3PoCv82013-05-15
CVE-2013-1311 [CRITICAL] CWE-416 CVE-2013-1311: Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arb Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."
nvd
CVE-2014-4141P2CRITICALCVSS 9.3PoCv8v9+2 more2014-10-15
CVE-2014-4141 [CRITICAL] CWE-119 CVE-2014-4141: Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-0040P2CRITICALCVSS 9.3PoCv112015-02-11
CVE-2015-0040 [CRITICAL] CVE-2015-0040: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0037, and CVE-2015-0066.
nvd
CVE-2015-1730P2CRITICALCVSS 9.3PoCv92015-06-10
CVE-2015-1730 [CRITICAL] CWE-399 CVE-2015-1730: Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
nvd
CVE-2015-6152P3CRITICALCVSS 9.3PoCv102015-12-09
CVE-2015-6152 [CRITICAL] CWE-119 CVE-2015-6152: Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial o Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6162.
nvd
CVE-2016-3387P2HIGHCVSS 7.5PoCv10v112016-10-14
CVE-2016-3387 [HIGH] CWE-264 CVE-2016-3387: Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3388.
nvd
CVE-2007-4790P3HIGHCVSS 7.5PoCv5.01v6+1 more2007-09-10
CVE-2007-4790 [HIGH] CWE-119 CVE-2007-4790: Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib. Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function.
nvd
CVE-2014-1795P2CRITICALCVSS 9.3PoCv9v10+1 more2014-06-11
CVE-2014-1795 [CRITICAL] CVE-2014-1795: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE
nvd
CVE-2014-1797P2CRITICALCVSS 9.3PoCv10v112014-06-11
CVE-2014-1797 [CRITICAL] CVE-2014-1797: Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a d Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2
nvd
CVE-2007-0217P3CRITICALCVSS 10.0PoCv5.01v6.02007-02-13
CVE-2007-0217 [CRITICAL] CVE-2007-0217: The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attacke The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
nvd
CVE-2002-1142P3HIGHCVSS 7.5PoCv5.0.1v5.5+1 more2002-11-29
CVE-2002-1142 [HIGH] CVE-2002-1142: Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Comp Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
nvd
Microsoft Internet Explorer vulnerabilities | cvebase