Internet Explorer
Vendor:
First CVE: Mar 1, 1997 · Active for 29 years
1,742
Total CVEs
More Total CVEs than 100% of tracked products
69.7
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Internet Explorer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 1997
29 years ago
Most Recent CVE
Aug 31, 2021
1,788 days ago
CVE Severity & Scoring
Internet Explorer1,742 CVEs
27%
69%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (0.3%)
Network449 (25.8%)
Unknown1,288 (73.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low143 (8.2%)
High311 (17.9%)
Unknown1,288 (73.9%)
User Interaction
None32 (1.8%)
Unknown1,288 (73.9%)
Required422 (24.2%)
Privileges Required
Low3 (0.2%)
High6 (0.3%)
None445 (25.5%)
Unknown1,288 (73.9%)
Top CVEs
Signals from CVEs in this product scope (1742 CVEs).
1,742 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0313CRITICAL Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta | Feb 2, 2015 | 9.8 | 98 | YES | YES |
CVE-2010-3962HIGH Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token | Nov 5, 2010 | 8.1 | 98 | YES | YES |
CVE-2010-0249HIGH Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP | Jan 15, 2010 | 8.8 | 98 | YES | YES |
CVE-2016-0189HIGH The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code o | May 11, 2016 | 7.5 | 97 | YES | YES |
CVE-2015-0311CRITICAL Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote a | Jan 23, 2015 | 9.8 | 97 | YES | YES |
CVE-2014-0322HIGH Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and t | Feb 14, 2014 | 8.8 | 97 | YES | YES |
CVE-2013-3893HIGH Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via c | Sep 18, 2013 | 8.8 | 97 | YES | YES |
CVE-2012-4792HIGH Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object t | Dec 30, 2012 | 8.8 | 97 | YES | YES |
CVE-2012-4969HIGH Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafte | Sep 18, 2012 | 8.1 | 97 | YES | YES |
CVE-2010-0806HIGH Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via ve | Mar 10, 2010 | 8.8 | 97 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (1742 CVEs).
CISA KEV
43 CVEs
2.5% of CVEs· 96th percentile
Metasploit
45 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
371 CVEs
21.3% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (1742 CVEs).
Media Mentions
Signals from CVEs in this product scope (1742 CVEs).
Top CNAs Publishing CVEs For Internet Explorer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 623 | 8.1 | 20.9% | 28 | 101 |
| 8.0b | 1 | 6.8 | 4.3% | 0 | 0 |
| 8.0.7100.0 | 1 | 5.0 | 11.0% | 0 | 1 |
| 8.0.6001 | 14 | 6.5 | 21.5% | 0 | 3 |
| 8 | 441 | 8.3 | 22.1% | 15 | 77 |
| 7.0.5730.11 | 19 | 6.2 | 20.6% | 0 | 3 |
| 7.0.5730 | 14 | 6.1 | 19.3% | 0 | 3 |
| 7.00.6000.16441 | 13 | 6.3 | 20.4% | 0 | 3 |
| 7.00.6000.16386 | 13 | 6.3 | 20.4% | 0 | 3 |
| 7.00.5730.1100 | 13 | 6.3 | 20.4% | 0 | 3 |
| 7.0 | 56 | 6.8 | 25.1% | 1 | 16 |
| 7 | 384 | 8.3 | 23.7% | 12 | 64 |
| 6.0.2900.2180 | 26 | 5.9 | 24.6% | 0 | 8 |
| 6.0.2900 | 32 | 6.0 | 19.1% | 0 | 5 |
| 6.0.2800.1106 | 26 | 6.3 | 24.8% | 0 | 7 |
| 6.0.2800 | 24 | 6.1 | 21.9% | 0 | 6 |
| 6.0.2600 | 25 | 6.0 | 19.9% | 0 | 5 |
| 6.00.3790.3959 | 12 | 6.4 | 19.3% | 0 | 1 |
| 6.00.3790.1830 | 12 | 6.4 | 19.3% | 0 | 1 |
| 6.00.3790.0000 | 12 | 6.4 | 19.3% | 0 | 1 |