Skip to main content

Vendor/product archive

microsoft / ie CVEs

Beta · best-effort

202 CVEs tagged to microsoft / ie25 Critical, 65 High, 93 Medium, 19 Low, 0 Unrated.

CVE-2012-1545

Published Mar 9, 2012

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5071

Published Dec 7, 2011

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2435

Published Dec 7, 2011

The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2383

Published Jun 3, 2011

Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-2382

Published Jun 3, 2011

Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2118

Published Jun 1, 2010

Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1991

Published May 20, 2010

Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which al…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2576

Published Jul 22, 2009

Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2433

Published Jul 10, 2009

Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2069

Published Jun 15, 2009

Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attack…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2057

Published Jun 15, 2009

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2281

Published May 18, 2008

Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1085

Published Apr 8, 2008

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that trigger…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0076

Published Feb 12, 2008

Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HT…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3903

Published Dec 12, 2007

Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeV…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5344

Published Dec 12, 2007

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses d…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5347

Published Dec 12, 2007

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vul…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4848

Published Sep 12, 2007

Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a J…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0943

Published Aug 14, 2007

Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memor…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3550

Published Jul 3, 2007

Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 202 CVEsPage 1 of 9