Microsoft Internet Explorer 11 vulnerabilities

161 known vulnerabilities affecting microsoft/internet_explorer_11.

Total CVEs
161
CISA KEV
13
actively exploited
Public exploits
15
Exploited in wild
17
Severity breakdown
HIGH128MEDIUM33

Vulnerabilities

Page 3 of 9
CVE-2020-0673HIGHCVSS 7.5vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for x64-based Systems+20 more2020-02-11
CVE-2020-0673 [HIGH] CVE-2020-0673: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
cvelistv5
CVE-2020-0706MEDIUMCVSS 4.3vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for x64-based Systems+17 more2020-02-11
CVE-2020-0706 [MEDIUM] CVE-2020-0706: An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cr An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'.
cvelistv5nvd
CVE-2020-0640HIGHCVSS 7.5vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for x64-based Systems+20 more2020-01-14
CVE-2020-0640 [HIGH] CWE-787 CVE-2020-0640: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
cvelistv5nvd
CVE-2019-1485HIGHCVSS 7.5vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for x64-based Systems+20 more2019-12-10
CVE-2019-1485 [HIGH] CWE-787 CVE-2019-1485: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
cvelistv5nvd
CVE-2019-1426HIGHCVSS 7.5vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+20 more2019-11-12
CVE-2019-1426 [HIGH] CWE-787 CVE-2019-1426: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1427, CVE-2019-1428, CVE-2019-1429.
nvd
CVE-2019-1390HIGHCVSS 7.5vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+20 more2019-11-12
CVE-2019-1390 [HIGH] CVE-2019-1390: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
cvelistv5nvd
CVE-2019-1429HIGHCVSS 7.5KEVPoCvWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+20 more2019-11-12
CVE-2019-1429 [HIGH] CVE-2019-1429: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
cvelistv5
CVE-2019-1371HIGHCVSS 7.5vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+22 more2019-10-10
CVE-2019-1371 [HIGH] CWE-787 CVE-2019-1371: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in m A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
cvelistv5nvd
CVE-2019-1238MEDIUMCVSS 6.4vWindows 10 Version 1809 for 32-bit SystemsvWindows 10 Version 1809 for x64-based Systems+2 more2019-10-10
CVE-2019-1238 [MEDIUM] CVE-2019-1238: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239.
cvelistv5nvd
CVE-2019-0608MEDIUMCVSS 4.3vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+22 more2019-10-10
CVE-2019-0608 [MEDIUM] CWE-290 CVE-2019-0608: A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'M A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.
cvelistv5nvd
CVE-2019-1357MEDIUMCVSS 4.3vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+22 more2019-10-10
CVE-2019-1357 [MEDIUM] CVE-2019-1357: A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability' A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
cvelistv5
CVE-2019-1239MEDIUMCVSS 6.4vWindows 10 Version 1809 for 32-bit SystemsvWindows 10 Version 1809 for x64-based Systems+2 more2019-10-10
CVE-2019-1239 [MEDIUM] CVE-2019-1239: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1238.
cvelistv5
CVE-2019-1367HIGHCVSS 7.5KEVvWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+21 more2019-09-23
CVE-2019-1367 [HIGH] CVE-2019-1367: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.
cvelistv5
CVE-2019-1221HIGHCVSS 7.5vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+21 more2019-09-11
CVE-2019-1221 [HIGH] CWE-787 CVE-2019-1221: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'.
cvelistv5nvd
CVE-2019-1208HIGHCVSS 7.5vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+22 more2019-09-11
CVE-2019-1208 [HIGH] CWE-416 CVE-2019-1208: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1236.
cvelistv5nvd
CVE-2019-1236HIGHCVSS 7.5vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+22 more2019-09-11
CVE-2019-1236 [HIGH] CVE-2019-1236: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1208.
cvelistv5
CVE-2019-1220MEDIUMCVSS 4.3vWindows 7 for 32-bit Systems Service Pack 1vWindows 7 for x64-based Systems Service Pack 1+22 more2019-09-11
CVE-2019-1220 [MEDIUM] CWE-425 CVE-2019-1220: A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'.
cvelistv5nvd
CVE-2019-1133HIGHCVSS 7.5≥ 1.0.0, < publication2019-08-14
CVE-2019-1133 [HIGH] CWE-787 CVE-2019-1133: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights a
cvelistv5nvd
CVE-2019-1194HIGHCVSS 7.5≥ 1.0.0, < publication2019-08-14
CVE-2019-1194 [HIGH] CWE-787 CVE-2019-1194: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights a
cvelistv5nvd
CVE-2019-1193MEDIUMCVSS 6.4≥ 1.0.0, < publication2019-08-14
CVE-2019-1193 [MEDIUM] CWE-787 CVE-2019-1193: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in me A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user
cvelistv5nvd