Internet Explorer Vulnerabilities
The following list includes some of the most critical Internet Explorer vulnerabilities known to the security community. In any case you find that there is anything missing in this list, please let us know and we will update it as soon as possible.
- Microsoft Internet Explorer SetExpandedClipRect Code Execution Vulnerability
- Microsoft Internet Explorer swapNode Handling Code Execution Vulnerability
- Microsoft Internet Explorer Select Element Insufficient Type Checking Code Execution Vulnerability
- Internet Explorer Select Element Cache Code Execution Vulnerability
- Microsoft Internet Explorer Protected Mode Bypass Vulnerability
- Microsoft Internet Explorer 9 STYLE Object Parsing Code Execution Vulnerability
- Microsoft Internet Explorer XSLT SetViewSlave Code Execution Vulnerability
- Microsoft Internet Explorer layout-grid-char style Code Execution Vulnerability
- Microsoft Internet Explorer DOM Modification Race Code Execution Vulnerability
- Microsoft Internet Explorer HTTP 302 Redirect Code Execution Vulnerability
- Microsoft Internet Explorer selection.empty Code Execution Vulnerability
- Microsoft Internet Explorer vgx.dll imagedata Code Execution Vulnerability
- Microsoft Internet Explorer Use-After-Free Memory Corruption Vulnerability
- Microsoft Internet Explorer Property Change Memory Corruption Vulnerability
- Microsoft Internet Explorer onPropertyChange Code Execution Vulnerability
- Microsoft Internet Explorer mshtml.dll Dangling Pointer Vulnerability
- Microsoft Internet Explorer Animation Use-after-free Vulnerability
- Microsoft Internet Explorer HTML+Time Element outerText Code Execution Vulnerability
- Microsoft Internet Explorer Recursive Select Element Code Execution Vulnerability
- Microsoft Internet Explorer HTML Object Memory Corruption Vulnerability
- Microsoft Internet Explorer CSS Style Table Layout Uninitialized Memory Vulnerability
- Microsoft Internet Explorer MSADO CacheSize Code Execution Vulnerability
- Microsoft Internet Explorer EOT File hdmx Parsing Code Execution Vulnerability
- Microsoft Internet Explorer Stylesheet PrivateFind Code Execution Vulnerability
- Microsoft Internet Explorer CIframeElement Object Use after free Vulnerability
- Microsoft Internet Explorer boundElements Property Use-after-free Vulnerability
- Firefox, Internet Explorer, Chrome and Opera Denial Of Service vulnerabilities
- Microsoft Internet Explorer Stylesheet Array Removal Code Execution Vulnerability
- Microsoft Internet Explorer onreadystatechange Use After Free Vulnerability
- Microsoft Internet Explorer TIME2 Behavior Remote Code Execution Vulnerability
- Microsoft Internet Explorer Dynamic OBJECT Tag and URLMON Sniffing Vulnerabilities
- Internet Explorer Multiple Remote Code Execution Vulnerabilities
- Microsoft Internet Explorer JScript arguments Invocation Memory Corruption
- Microsoft Internet Explorer Use After Free Vulnerability
- Microsoft Internet Explorer CSS Behavior Memory Corruption Vulnerability
- Microsoft Internet Explorer Memory Corruption Vulnerability
- Microsoft Internet Explorer 8 Pointer Code Execution Vulnerability (MS09-019)
- Microsoft Internet Explorer setCapture Memory Corruption Vulnerability (MS09-019)
- Microsoft Internet Explorer Security Zone Restrictions Bypass
- Microsoft Internet Explorer onreadystatechange Memory Corruption Vulnerability (MS09-019)
- Microsoft Internet Explorer Event Handler Memory Corruption Vulnerability (MS09-019)
- Microsoft Internet Explorer DHTML Handling Memory Corruption Vulnerability (MS09-019)
- Microsoft Internet Explorer Concurrent Ajax Request Memory Corruption (MS09-019)
- Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities
- Microsoft Internet Explorer HTML Tag Long File Name Extension Stack Buffer Overflow Vulnerability (MS08-073)
- Cumulative Security Update for Internet Explorer (MS08-058)
- Microsoft Windows GDI+ Gradient Fill Heap Overflow Vulnerability
- Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass (MS08-043)
- Cumulative Security Update for Internet Explorer (MS08-045)
- Cumulative Security Update for Internet Explorer (MS08-031)
- Cumulative Security Update for Internet Explorer (MS08-024)
- Security Update of ActiveX Kill Bits (MS08-023)
- Microsoft Internet Explorer FTP Command Injection Vulnerability
- Microsoft Internet Explorer Property Memory Corruption Vulnerability
- Microsoft Internet Explorer JavaScript setExpression Heap Corruption Vulnerability
- Cumulative Security Update for Internet Explorer (MS07-069)
- Cumulative Security Update for Internet Explorer (MS07-057)
- Cumulative Security Update for Internet Explorer (MS07-045)
- Microsoft XML Core Services XMLDOM Memory Corruption Vulnerability
- Phishing Using IE7 Local Resource Vulnerability
- Multiple Browsers Cross Domain Charset Inheritance Vulnerability
- Microsoft \wininet.dll\ FTP Reply Null Termination Heap Corruption Vulnerability
- MS Internet Explorer 6 Null Pointer Dereference Exploit (mshtml.dll)
- Microsoft Windows VML Element Integer Overflow
- Internet Explorer 7 "mhtml:" Redirection Information Disclosure
- Internet Explorer \ADODB.Connection\ Object \Execute\ Function DoS (Exploit)
- Internet Explorer VML Buffer Overflow Download Exec (Exploit)
- Internet Explorer COM Object Heap Overflow Download Exec (Exploit)
- Internet Explorer Compressed Content URL Heap Overflow 2
- Microsoft Internet Explorer daxctle.ocx Heap Overflow
- Internet Explorer Compressed Content URL Heap Overflow
- Internet Explorer Multiple COM Objects Color Property DoS
- Windows 2000 Multiple COM Object Instantiation Vulnerability
- Visual Studio 6.0 Multiple COM Object Instantiation Vulnerability
- Microsoft Internet Explorer UTF-8 Decoding Heap Overflow Vulnerability
- Microsoft Internet Explorer DXImageTransform ActiveX Memory Corruption Vulnerability
- Multiple Browsers File Upload Data Disclosure
- Internet Explorer Null Pointer Dereference DoS
- Microsoft Internet Explorer Crash
- Interner Explorer Interpreter Stack Overflow
- Internet Explorer CSS Attribute DoS
- Microsoft Internet Explorer DoS
- Internet Explorer Script Action Handlers (mshtml.dll) Buffer Overflow
- WMF Image Parsing Memory Corruption (MS06-004)
- Internet Explorer 7.0 Beta 2 urlmon.dll Buffer Overflow
- Internet Explorer XML and IMG Elements DoS
- Microsoft Internet Explorer Multiple DoS (datasrc, mshtml.dll)
- Microsoft Internet Explorer Keyboard Shortcut Processing
- Internet Explorer Multiple Download Dialog Vulnerabilities (MS05-054)
- Microsoft Office InfoPath 2003 Form Handling DoS
- Microsoft Internet Explorer JavaScript Window() Code Execution
- Microsoft Internet Explorer Msdds.dll Code Execution
- Cumulative Security Update for Internet Explorer (MS05-038, Exploit)
- Internet Explorer Code Execution Through MIME Manipulation
- Microsoft IE Devenum.dll COM Instantiation Code Execution
- Microsoft Internet Explorer COM Objects Instantiation (Exploit, MS05-038)
- Cumulative Security Update for Internet Explorer (MS05-038)
- Microsoft Internet Explorer Javaprxy.dll COM Object Execution (Exploit)
- Multiple Browsers Dialog Origin Vulnerability (Test)
- Internet Explorer and Opera JavaScript Ghost Vulnerability
- Microsoft IE Recursive Scripting, Embedded Files, window() and Restricted Sites DoS
- Internet Explorer wininet.dll URL Parsing Memory Corruption (Technical Details, MS05-020)
- Multiple Vulnerabilities in Internet Explorer (Heap Corruption, Race Condition)
- Microsoft Internet Explorer createControlRange() Memory Corruption
- Microsoft Internet Explorer Multiple Vulnerabilities (Content-Disposition, codebase)
- Internet Explorer Handling of %20 Allows Spoofing
- Internet Explorer FTP Client Directory Traversal
- Browsers\ FTP Client can be Used to Send Mail
- Microsoft Internet Explorer XP SP2 Fully Automated Remote Compromise
- FTP Client Command Injection
- Windows XP SP2 Popup Blocker Bypassing
- Sun Java Plugin Arbitrary Package Access Vulnerability
- Circumvent Windows XP SP2 Security Features using execCommand \SaveAs\ Function
- How to Break Windows XP SP2 (Drag and Drop media files)
- Poisoning Cached HTTPS Documents in Internet Explorer
- Internet Explorer Remote Null Pointer Crash (mshtml.dll)
- Internet Explorer Method Cache Location Variant Trust Leads to Script Execution
- Sun JVM Insecure Temporary File Creation Allows Remote Code Execution
- Internet Explorer Memory Corruption Bug
- Removing about:blank Homepage Hijacker
- Internet Explorer Crash (Malformed META Tag)
- Internet Explorer Remote Dos (Memory Access Violation)
- Internet Explorer Print without Prompting
- Microsoft Internet Explorer Cross Frame Scripting Restriction Bypass
- AOL Instant Messenger/Microsoft Internet Explorer Remote Code Execution
- Internet Explorer/Outlook double null character DoS
- Internet Explorer JavaScript URL Injection in History List
- Microsoft Internet Explorer %USERPROFILE% File Execution Vulnerability
- Internet Explorer Local Zone Restriction Bypass (Exploit)
- Cumulative Patch for Internet Explorer (MS03-040)
- Internet Explorer Object Data Remote Execution Vulnerability
- The Return of the Content-Disposition Vulnerability in IE
- Internet Explorer Object Type Buffer Overflow in Double-Byte Character Set Environment
- Microsoft Internet Explorer about:blank Cross Site Scripting
- Unchecked Buffer in DirectX Could Enable System Compromise
- Script Injection to Custom HTTP Errors in Local Zone
- Cross-Site Scripting in Unparsable XML Files
- Internet Explorer Program Execution (Flooding)
- MHT Buffer Overflow in Internet Explorer
- Cumulative Patch for Internet Explorer (MS03-004)
- PNG (Portable Network Graphics) Deflate Heap Corruption Vulnerability (Windows)
- Poisonous Style for Dialog Window Bypasses Zone Security
- Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution
- Bypassing Cookie Restrictions in IE 5 and IE 6
- Microsoft Internet Explorer % Encoding Security Issue (CSS)
- Certificate Validation Flaw Could Enable Identity Spoofing
- Internet Explorer SSL Vulnerability
- Macromedia Shockwave Flash Malformed Header Overflow
- Combining IE and .XLA leads to Security Vulnerabilities
- IE Allows Universal Cross Domain Scripting
- IE CSS Parsing Error (cssText)
- Unchecked Buffer in Gopher Protocol Handler Can Run Code of Attacker\s Choice
- IE \Folder View for FTP sites\ Script Execution Vulnerability
- 15 May 2002 Cumulative Patch for Internet Explorer
- IE and OE Cannot Handle Malformed XBM Files
- MSIE URL Buffer Overflow using Greek Characters
- Unchecked Buffer in Internet Explorer and Office for Mac Can Cause Code to Execute
- 28 March 2002 Cumulative Patch for Internet Explorer
- Automatically Opening Internet Explorer and Execution of Attachments (WebBrowser)
- Internet Explorer and Access Allows Macros to be Executed Automatically
- Web Browsers Vulnerable to the Extended HTML Form Attack
- 13 December 2001 Cumulative Patch for IE
- November 2001 Cumulative Patch for IE
- Cookie Data in IE Can Be Exposed or Altered Through Script Injection
- Downloaded Applications Can Execute Without Warning on Mac IE 5.1 for OS X
- Dotless IP Addresses Can Cause IE to Move into Intranet Zone
- Flaws in Web Server Certificate Validation Could Enable Spoofing
- Automatic Execution of Embedded MIME Types Vulnerability
- Incorrect MIME Headers Can Cause IE to Execute E-mail Attachments