Microsoft
Microsoft Internet Explorer: vulnerabilidades y CVE
Microsoft Internet Explorer tiene 1644 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 6 son críticas y 43 figuran en el catálogo de explotación activa de CISA.
CVE1644
Últimos 12 meses1
Críticas6
Explotadas activamente43
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2010-0249 | Alta (8.8) | 92% | ⚠ Explotación activa | 15 ene 2010 | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and… |
| CVE-2010-0806 | Alta (8.8) | 82% | ⚠ Explotación activa | 10 mar 2010 | Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid… |
| CVE-2010-3962 | Alta (8.1) | 97% | ⚠ Explotación activa | 5 nov 2010 | Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka… |
| CVE-2013-3893 | Alta (8.8) | 88% | ⚠ Explotación activa | 18 sept 2013 | Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as… |
| CVE-2012-4792 | Alta (8.8) | 79% | ⚠ Explotación activa | 30 dic 2012 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or… |
| CVE-2013-3163 | Alta (8.8) | 71% | ⚠ Explotación activa | 10 jul 2013 | Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption… |
| CVE-2012-4969 | Alta (8.1) | 80% | ⚠ Explotación activa | 18 sept 2012 | Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in… |
| CVE-2014-4123 | Alta (8.8) | 47% | ⚠ Explotación activa | 15 oct 2014 | Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a… |
| CVE-2013-7331 | Media (6.5) | 50% | ⚠ Explotación activa | 26 feb 2014 | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by… |
| CVE-2014-2817 | Alta (8.8) | 26% | ⚠ Explotación activa | 12 ago 2014 | Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." |
| CVE-2015-0071 | Media (6.5) | 34% | ⚠ Explotación activa | 11 feb 2015 | Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability." |
| CVE-2015-2425 | Alta (8.8) | 45% | ⚠ Explotación activa | 14 jul 2015 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a… |
| CVE-2017-0149 | Alta (8.8) | 29% | ⚠ Explotación activa | 17 mar 2017 | Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."… |
| CVE-2017-0210 | Alta (8.8) | 22% | ⚠ Explotación activa | 12 abr 2017 | An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another… |
| CVE-2016-0162 | Media (4.3) | 22% | ⚠ Explotación activa | 12 abr 2016 | Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability." |
| CVE-2016-3351 | Media (6.5) | 26% | ⚠ Explotación activa | 14 sept 2016 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." |
| CVE-2016-3298 | Media (6.5) | 33% | ⚠ Explotación activa | 14 oct 2016 | Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files… |
| CVE-2019-0676 | Media (6.5) | 8.1% | ⚠ Explotación activa | 5 mar 2019 | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka… |
| CVE-2014-0322 | Alta (8.8) | 85% | ⚠ Explotación activa | 14 feb 2014 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a… |
| CVE-2015-0311 | Crítica (9.8) | 86% | ⚠ Explotación activa | 23 ene 2015 | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9264 | Crítica (9.3) | 0.26% | — | 22 may 2026 | A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from… |
| CVE-2025-31488 | Media (5) | 0.18% | — | 6 abr 2025 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the… |
| CVE-2021-26419 | Alta (7.5) | 23% | — | 11 may 2021 | Scripting Engine Memory Corruption Vulnerability |
| CVE-2021-27085 | Alta (8.8) | 5.4% | ⚠ Explotación activa | 11 mar 2021 | Internet Explorer Remote Code Execution Vulnerability |
| CVE-2021-26411 | Alta (8.8) | 81% | ⚠ Explotación activa | 11 mar 2021 | Internet Explorer Memory Corruption Vulnerability |
| CVE-2020-17058 | Alta (7.5) | 3.1% | — | 11 nov 2020 | Microsoft Browser Memory Corruption Vulnerability |
| CVE-2020-17053 | Alta (7.5) | 3.2% | — | 11 nov 2020 | Internet Explorer Memory Corruption Vulnerability |
| CVE-2020-17052 | Alta (8.1) | 2.7% | — | 11 nov 2020 | Scripting Engine Memory Corruption Vulnerability |
| CVE-2020-1506 | Alta (8.8) | 2.1% | — | 11 sept 2020 | <p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p>… |
| CVE-2020-1012 | Alta (8.8) | 3.7% | — | 11 sept 2020 | <p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p>… |
| CVE-2020-0878 | Alta (7.5) | 2.7% | ⚠ Explotación activa | 11 sept 2020 | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the… |
| CVE-2020-1570 | Alta (7.5) | 8.8% | — | 17 ago 2020 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute… |
| CVE-2020-1567 | Alta (7.5) | 3.7% | — | 17 ago 2020 | A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on… |
| CVE-2020-1380 | Alta (8.8) | 24% | ⚠ Explotación activa | 17 ago 2020 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute… |
| CVE-2020-1432 | Media (4.3) | 4.5% | — | 14 jul 2020 | An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'. |
| CVE-2020-1403 | Alta (7.5) | 10% | — | 14 jul 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. |
| CVE-2020-1315 | Media (5.3) | 3.8% | — | 9 jun 2020 | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. |
| CVE-2020-1260 | Alta (7.5) | 7.2% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,… |
| CVE-2020-1230 | Alta (7.5) | 7.1% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,… |
| CVE-2020-1219 | Alta (7.5) | 19% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. |
| CVE-2020-1216 | Alta (7.5) | 7.2% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,… |
| CVE-2020-1215 | Alta (7.5) | 8.0% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214,… |
| CVE-2020-1214 | Alta (7.5) | 8.0% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1215,… |
| CVE-2020-1213 | Alta (7.5) | 7.2% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215,… |
| CVE-2020-1093 | Alta (7.5) | 3.1% | — | 21 may 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the… |
| CVE-2020-1092 | Alta (7.5) | 3.1% | — | 21 may 2020 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the… |
| CVE-2020-1064 | Alta (7.5) | 3.1% | — | 21 may 2020 | A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on… |
| CVE-2020-1062 | Alta (7.5) | 6.2% | — | 21 may 2020 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the… |
| CVE-2020-1060 | Alta (7.5) | 3.1% | — | 21 may 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the… |
| CVE-2020-1058 | Alta (7.5) | 3.1% | — | 21 may 2020 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.