Internet Explorer
by Microsoft
CVEs (1,725)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0802 | 0.01 | — | 0.10 | May 27, 1999 | Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. | |||
| CVE-1999-0489 | 0.01 | — | 0.12 | May 17, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | |||
| CVE-1999-1241 | 0.01 | — | 0.14 | May 6, 1999 | Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. | |||
| CVE-1999-0490 | 0.01 | — | 0.10 | Apr 21, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag. | |||
| CVE-1999-0488 | 0.01 | — | 0.12 | Apr 21, 1999 | Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. | |||
| CVE-1999-0469 | 0.01 | — | 0.17 | Apr 1, 1999 | Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. | |||
| CVE-1999-0870 | 0.01 | — | 0.13 | Oct 1, 1998 | Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. | |||
| CVE-1999-0871 | 0.01 | — | 0.12 | Sep 4, 1998 | Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. | |||
| CVE-1999-1447 | 0.01 | — | 0.13 | Jul 28, 1998 | Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. | |||
| CVE-1999-0967 | 0.01 | — | 0.07 | Nov 1, 1997 | Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. | |||
| CVE-1999-0031 | 0.01 | — | 0.18 | Jul 8, 1997 | JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. | |||
| CVE-1999-0280 | 0.01 | — | 0.15 | Apr 1, 1997 | Remote command execution in Microsoft Internet Explorer using .lnk and .url files. | |||
| CVE-2021-31959 | 0.00 | — | 0.09 | Jun 8, 2021 | Scripting Engine Memory Corruption Vulnerability | |||
| CVE-2020-17058 | 0.00 | — | 0.03 | Nov 11, 2020 | Microsoft Browser Memory Corruption Vulnerability | |||
| CVE-2020-17053 | 0.00 | — | 0.03 | Nov 11, 2020 | Internet Explorer Memory Corruption Vulnerability | |||
| CVE-2020-1506 | 0.00 | — | 0.02 | Sep 11, 2020 | An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. There are multiple ways an attacker could exploit the… | |||
| CVE-2020-1570 | 0.00 | — | 0.09 | Aug 17, 2020 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker… | |||
| CVE-2020-1567 | 0.00 | — | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully… | |||
| CVE-2020-1315 | 0.00 | — | 0.04 | Jun 9, 2020 | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. | |||
| CVE-2020-1260 | 0.00 | — | 0.07 | Jun 9, 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230. |
- CVE-1999-0802May 27, 1999risk 0.01cvss —epss 0.10
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.
- CVE-1999-0489May 17, 1999risk 0.01cvss —epss 0.12
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
- CVE-1999-1241May 6, 1999risk 0.01cvss —epss 0.14
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.
- CVE-1999-0490Apr 21, 1999risk 0.01cvss —epss 0.10
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.
- CVE-1999-0488Apr 21, 1999risk 0.01cvss —epss 0.12
Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.
- CVE-1999-0469Apr 1, 1999risk 0.01cvss —epss 0.17
Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.
- CVE-1999-0870Oct 1, 1998risk 0.01cvss —epss 0.13
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
- CVE-1999-0871Sep 4, 1998risk 0.01cvss —epss 0.12
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.
- CVE-1999-1447Jul 28, 1998risk 0.01cvss —epss 0.13
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.
- CVE-1999-0967Nov 1, 1997risk 0.01cvss —epss 0.07
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
- CVE-1999-0031Jul 8, 1997risk 0.01cvss —epss 0.18
JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.
- CVE-1999-0280Apr 1, 1997risk 0.01cvss —epss 0.15
Remote command execution in Microsoft Internet Explorer using .lnk and .url files.
- CVE-2021-31959Jun 8, 2021risk 0.00cvss —epss 0.09
Scripting Engine Memory Corruption Vulnerability
- CVE-2020-17058Nov 11, 2020risk 0.00cvss —epss 0.03
Microsoft Browser Memory Corruption Vulnerability
- CVE-2020-17053Nov 11, 2020risk 0.00cvss —epss 0.03
Internet Explorer Memory Corruption Vulnerability
- CVE-2020-1506Sep 11, 2020risk 0.00cvss —epss 0.02
An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. There are multiple ways an attacker could exploit the…
- CVE-2020-1570Aug 17, 2020risk 0.00cvss —epss 0.09
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker…
- CVE-2020-1567Aug 17, 2020risk 0.00cvss —epss 0.04
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully…
- CVE-2020-1315Jun 9, 2020risk 0.00cvss —epss 0.04
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
- CVE-2020-1260Jun 9, 2020risk 0.00cvss —epss 0.07
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230.
Page 81 of 87