target entity

Internet Explorer

36 source-linked records in the current knowledge graph.

high

CVE-2010-0249: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-0249EPSS 91.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0806: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-0806EPSS 82.2%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2010-3962: Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-3962EPSS 96.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3893: Microsoft Internet Explorer Resource Management Errors Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3893EPSS 85.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2012-4792: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-4792EPSS 78.8%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3163: Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-3163EPSS 70.7%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3298: Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk. Required action: Apply updates per vendor instructions.

CVE-2016-3298EPSS 32.8%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0676: Microsoft Internet Explorer Information Disclosure Vulnerability

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk. Required action: Apply updates per vendor instructions.

CVE-2019-0676EPSS 7.5%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-0189: Microsoft Internet Explorer Memory Corruption Vulnerability

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2016-0189EPSS 93.2%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution