« Volver al listado

Microsoft

Microsoft Internet Explorer: vulnerabilidades y CVE

Microsoft Internet Explorer tiene 1644 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 6 son críticas y 43 figuran en el catálogo de explotación activa de CISA.

CVE1644
Últimos 12 meses1
Críticas6
Explotadas activamente43

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2010-0249Alta (8.8)92%⚠ Explotación activa15 ene 2010
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and…
CVE-2010-0806Alta (8.8)82%⚠ Explotación activa10 mar 2010
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid…
CVE-2010-3962Alta (8.1)97%⚠ Explotación activa5 nov 2010
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka…
CVE-2013-3893Alta (8.8)88%⚠ Explotación activa18 sept 2013
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as…
CVE-2012-4792Alta (8.8)79%⚠ Explotación activa30 dic 2012
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or…
CVE-2013-3163Alta (8.8)71%⚠ Explotación activa10 jul 2013
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption…
CVE-2012-4969Alta (8.1)80%⚠ Explotación activa18 sept 2012
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in…
CVE-2014-4123Alta (8.8)47%⚠ Explotación activa15 oct 2014
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a…
CVE-2013-7331Media (6.5)50%⚠ Explotación activa26 feb 2014
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by…
CVE-2014-2817Alta (8.8)26%⚠ Explotación activa12 ago 2014
Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
CVE-2015-0071Media (6.5)34%⚠ Explotación activa11 feb 2015
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
CVE-2015-2425Alta (8.8)45%⚠ Explotación activa14 jul 2015
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a…
CVE-2017-0149Alta (8.8)29%⚠ Explotación activa17 mar 2017
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."…
CVE-2017-0210Alta (8.8)22%⚠ Explotación activa12 abr 2017
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another…
CVE-2016-0162Media (4.3)22%⚠ Explotación activa12 abr 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."
CVE-2016-3351Media (6.5)26%⚠ Explotación activa14 sept 2016
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
CVE-2016-3298Media (6.5)33%⚠ Explotación activa14 oct 2016
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files…
CVE-2019-0676Media (6.5)8.1%⚠ Explotación activa5 mar 2019
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka…
CVE-2014-0322Alta (8.8)85%⚠ Explotación activa14 feb 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a…
CVE-2015-0311Crítica (9.8)86%⚠ Explotación activa23 ene 2015
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-9264Crítica (9.3)0.26%—22 may 2026
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from…
CVE-2025-31488Media (5)0.18%—6 abr 2025
Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the…
CVE-2021-26419Alta (7.5)23%—11 may 2021
Scripting Engine Memory Corruption Vulnerability
CVE-2021-27085Alta (8.8)5.4%⚠ Explotación activa11 mar 2021
Internet Explorer Remote Code Execution Vulnerability
CVE-2021-26411Alta (8.8)81%⚠ Explotación activa11 mar 2021
Internet Explorer Memory Corruption Vulnerability
CVE-2020-17058Alta (7.5)3.1%—11 nov 2020
Microsoft Browser Memory Corruption Vulnerability
CVE-2020-17053Alta (7.5)3.2%—11 nov 2020
Internet Explorer Memory Corruption Vulnerability
CVE-2020-17052Alta (8.1)2.7%—11 nov 2020
Scripting Engine Memory Corruption Vulnerability
CVE-2020-1506Alta (8.8)2.1%—11 sept 2020
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p>…
CVE-2020-1012Alta (8.8)3.7%—11 sept 2020
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p>…
CVE-2020-0878Alta (7.5)2.7%⚠ Explotación activa11 sept 2020
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the…
CVE-2020-1570Alta (7.5)8.8%—17 ago 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute…
CVE-2020-1567Alta (7.5)3.7%—17 ago 2020
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on…
CVE-2020-1380Alta (8.8)24%⚠ Explotación activa17 ago 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute…
CVE-2020-1432Media (4.3)4.5%—14 jul 2020
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
CVE-2020-1403Alta (7.5)10%—14 jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
CVE-2020-1315Media (5.3)3.8%—9 jun 2020
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
CVE-2020-1260Alta (7.5)7.2%—9 jun 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,…
CVE-2020-1230Alta (7.5)7.1%—9 jun 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,…
CVE-2020-1219Alta (7.5)19%—9 jun 2020
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
CVE-2020-1216Alta (7.5)7.2%—9 jun 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,…
CVE-2020-1215Alta (7.5)8.0%—9 jun 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,…
CVE-2020-1214Alta (7.5)8.0%—9 jun 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1215,…
CVE-2020-1213Alta (7.5)7.2%—9 jun 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215,…
CVE-2020-1093Alta (7.5)3.1%—21 may 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the…
CVE-2020-1092Alta (7.5)3.1%—21 may 2020
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the…
CVE-2020-1064Alta (7.5)3.1%—21 may 2020
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on…
CVE-2020-1062Alta (7.5)6.2%—21 may 2020
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the…
CVE-2020-1060Alta (7.5)3.1%—21 may 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the…
CVE-2020-1058Alta (7.5)3.1%—21 may 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution19
  2. T1059 Command and Scripting Interpreter14
  3. T1005 Data from Local System4
  4. T1204.002 Malicious File4
  5. T1499.004 Application or System Exploitation4
  6. T1574 Hijack Execution Flow4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft