Internet Explorer

Vendor:

First CVE: Mar 1, 1997 · Active for 29 years

1,742
Total CVEs
More Total CVEs than 100% of tracked products
69.7
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Internet Explorer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 1997
29 years ago
Most Recent CVE
Aug 31, 2021
1,788 days ago

CVE Severity & Scoring

Internet Explorer1,742 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local5 (0.3%)
Network449 (25.8%)
Unknown1,288 (73.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low143 (8.2%)
High311 (17.9%)
Unknown1,288 (73.9%)
User Interaction
None32 (1.8%)
Unknown1,288 (73.9%)
Required422 (24.2%)
Privileges Required
Low3 (0.2%)
High6 (0.3%)
None445 (25.5%)
Unknown1,288 (73.9%)

Top CVEs

Signals from CVEs in this product scope (1742 CVEs).

1,742 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta
Feb 2, 20159.898YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token
Nov 5, 20108.198YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP
Jan 15, 20108.898YESYES
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code o
May 11, 20167.597YESYES
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote a
Jan 23, 20159.897YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and t
Feb 14, 20148.897YESYES
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via c
Sep 18, 20138.897YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object t
Dec 30, 20128.897YESYES
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafte
Sep 18, 20128.197YESYES
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via ve
Mar 10, 20108.897YESYES

Exploit Exposure

Signals from CVEs in this product scope (1742 CVEs).

CISA KEV
43 CVEs
2.5% of CVEs· 96th percentile
Metasploit
45 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
371 CVEs
21.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (1742 CVEs).

Media Mentions

Signals from CVEs in this product scope (1742 CVEs).

Top CNAs Publishing CVEs For Internet Explorer

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
96238.120.9%28101
8.0b16.84.3%00
8.0.7100.015.011.0%01
8.0.6001146.521.5%03
84418.322.1%1577
7.0.5730.11196.220.6%03
7.0.5730146.119.3%03
7.00.6000.16441136.320.4%03
7.00.6000.16386136.320.4%03
7.00.5730.1100136.320.4%03
7.0566.825.1%116
73848.323.7%1264
6.0.2900.2180265.924.6%08
6.0.2900326.019.1%05
6.0.2800.1106266.324.8%07
6.0.2800246.121.9%06
6.0.2600256.019.9%05
6.00.3790.3959126.419.3%01
6.00.3790.1830126.419.3%01
6.00.3790.0000126.419.3%01