Internet Explorer
by Microsoft
CVEs (1,731)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0793 | 0.04 | — | 0.13 | Nov 17, 1999 | Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. | |||
| CVE-1999-1110 | 0.04 | — | 0.10 | Nov 14, 1999 | Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. | |||
| CVE-2000-0329 | 0.04 | — | 0.08 | Nov 11, 1999 | A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. | |||
| CVE-1999-0877 | 0.04 | — | 0.18 | Oct 1, 1999 | Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. | |||
| CVE-1999-0669 | 0.04 | — | 0.09 | Sep 1, 1999 | The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. | |||
| CVE-1999-1016 | 0.04 | — | 0.08 | Aug 27, 1999 | Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as… | |||
| CVE-1999-0487 | 0.04 | — | 0.13 | May 1, 1999 | The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. | |||
| CVE-1999-1453 | 0.04 | — | 0.11 | Feb 2, 1999 | Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. | |||
| CVE-1999-0869 | 0.04 | — | 0.17 | Dec 1, 1998 | Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. | |||
| CVE-2015-1692 | 0.03 | — | 0.35 | May 13, 2015 | Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard contents via crafted web script, aka "Internet Explorer Clipboard Information Disclosure Vulnerability." | |||
| CVE-2014-4109 | 0.03 | — | 0.31 | Sep 10, 2014 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799,… | |||
| CVE-2014-0271 | 0.03 | — | 0.38 | Feb 12, 2014 | The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability." | |||
| CVE-2013-3908 | 0.03 | — | 0.36 | Nov 13, 2013 | Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer… | |||
| CVE-2013-4015 | 0.03 | — | 0.03 | Jul 26, 2013 | Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code. | |||
| CVE-2011-2001 | 0.03 | — | 0.43 | Oct 12, 2011 | Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual Function Table Corruption… | |||
| CVE-2011-1961 | 0.03 | — | 0.34 | Aug 10, 2011 | The telnet URI handler in Microsoft Internet Explorer 6 through 9 does not properly launch the handler application, which allows remote attackers to execute arbitrary programs via a crafted web site, aka "Telnet Handler Remote Code Execution Vulnerability." | |||
| CVE-2011-1345 | 0.03 | — | 0.41 | Mar 10, 2011 | Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three… | |||
| CVE-2010-1262 | 0.03 | — | 0.33 | Jun 8, 2010 | Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container,… | |||
| CVE-2010-0267 | 0.03 | — | 0.34 | Mar 31, 2010 | Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory… | |||
| CVE-2010-0255 | 0.03 | — | 0.37 | Feb 4, 2010 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that… |
- CVE-1999-0793Nov 17, 1999risk 0.04cvss —epss 0.13
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
- CVE-1999-1110Nov 14, 1999risk 0.04cvss —epss 0.10
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.
- CVE-2000-0329Nov 11, 1999risk 0.04cvss —epss 0.08
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
- CVE-1999-0877Oct 1, 1999risk 0.04cvss —epss 0.18
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
- CVE-1999-0669Sep 1, 1999risk 0.04cvss —epss 0.09
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
- CVE-1999-1016Aug 27, 1999risk 0.04cvss —epss 0.08
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as…
- CVE-1999-0487May 1, 1999risk 0.04cvss —epss 0.13
The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.
- CVE-1999-1453Feb 2, 1999risk 0.04cvss —epss 0.11
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.
- CVE-1999-0869Dec 1, 1998risk 0.04cvss —epss 0.17
Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
- CVE-2015-1692May 13, 2015risk 0.03cvss —epss 0.35
Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard contents via crafted web script, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."
- CVE-2014-4109Sep 10, 2014risk 0.03cvss —epss 0.31
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799,…
- CVE-2014-0271Feb 12, 2014risk 0.03cvss —epss 0.38
The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."
- CVE-2013-3908Nov 13, 2013risk 0.03cvss —epss 0.36
Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer…
- CVE-2013-4015Jul 26, 2013risk 0.03cvss —epss 0.03
Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.
- CVE-2011-2001Oct 12, 2011risk 0.03cvss —epss 0.43
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual Function Table Corruption…
- CVE-2011-1961Aug 10, 2011risk 0.03cvss —epss 0.34
The telnet URI handler in Microsoft Internet Explorer 6 through 9 does not properly launch the handler application, which allows remote attackers to execute arbitrary programs via a crafted web site, aka "Telnet Handler Remote Code Execution Vulnerability."
- CVE-2011-1345Mar 10, 2011risk 0.03cvss —epss 0.41
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three…
- CVE-2010-1262Jun 8, 2010risk 0.03cvss —epss 0.33
Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container,…
- CVE-2010-0267Mar 31, 2010risk 0.03cvss —epss 0.34
Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory…
- CVE-2010-0255Feb 4, 2010risk 0.03cvss —epss 0.37
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that…
Page 39 of 87