Ie

Vendor:

First CVE: Nov 1, 1999 · Active for 26 years

202
Total CVEs
More Total CVEs than 99% of tracked products
14.4
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ie over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 1999
26 years ago
Most Recent CVE
Mar 9, 2012
5,251 days ago

CVE Severity & Scoring

Ie202 CVEs
All CVEs352,427 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (0.5%)
Unknown201 (99.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (0.5%)
High0 (0.0%)
Unknown201 (99.5%)
User Interaction
None0 (0.0%)
Unknown201 (99.5%)
Required1 (0.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (0.5%)
Unknown201 (99.5%)

Top CVEs

Signals from CVEs in this product scope (202 CVEs).

202 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other W
Sep 14, 20067.684NOYES
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag i
Jun 16, 20037.583NOYES
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox
Mar 23, 20069.380NOYES
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as
Dec 31, 200410.077NOYES
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows re
Nov 29, 20027.577NOYES
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argumen
Jul 21, 20068.874NOYES
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malfo
Mar 30, 20079.373NOYES
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via
Aug 6, 200410.070NOYES
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
Apr 11, 20067.569NOYES
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length tha
Feb 13, 200710.067NOYES

Exploit Exposure

Signals from CVEs in this product scope (202 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
3.0% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
75 CVEs
37.1% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (202 CVEs).

Media Mentions

Signals from CVEs in this product scope (202 CVEs).

Top CNAs Publishing CVEs For Ie

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
924.320.1%00
8.0b45.717.1%02
8.0.7600.1638544.711.8%00
7.0.6000.1671124.713.2%00
7.0146.124.7%08
747.726.5%01
6.01216.627.5%051
6445.926.0%017
5.x66.220.6%01
5.2.346.032.2%02
5.2245.49.0%00
5.215.014.9%00
5.1.715.014.9%00
5.1.115.014.9%00
5.156.330.6%03
5.0_ta335.721.8%01
5.0.176.022.3%02
5.0187.134.6%03
5.0154.710.4%04
575.410.2%03