Vbscript
Vendor:
First CVE: Apr 13, 2011 · Active for 15 years
23
Total CVEs
More Total CVEs than 95% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
4.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Vbscript over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2011
15 years ago
Most Recent CVE
Jun 16, 2016
3,690 days ago
CVE Severity & Scoring
Vbscript23 CVEs
22%
78%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (34.8%)
Unknown15 (65.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.3%)
High7 (30.4%)
Unknown15 (65.2%)
User Interaction
None0 (0.0%)
Unknown15 (65.2%)
Required8 (34.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (34.8%)
Unknown15 (65.2%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-0189HIGH The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code o | May 11, 2016 | 7.5 | 97 | YES | YES |
CVE-2014-6363HIGH vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a den | Dec 11, 2014 | 9.3 | 55 | NO | YES |
CVE-2015-2482HIGH The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrar | Oct 14, 2015 | 9.3 | 50 | NO | YES |
CVE-2014-0271HIGH The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or cause a denial of service (memor | Feb 12, 2014 | 9.3 | 42 | NO | NO |
CVE-2012-2523HIGH Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorr | Aug 15, 2012 | 9.3 | 40 | NO | NO |
CVE-2011-0663HIGH Multiple integer overflows in the Microsoft (1) JScript 5.6 through 5.8 and (2) VBScript 5.6 through 5.8 scripting engines allow remote attackers to execute arbitrary code via a cr | Apr 13, 2011 | 8.8 | 37 | NO | NO |
CVE-2015-6055HIGH The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrar | Oct 14, 2015 | 9.3 | 36 | NO | NO |
CVE-2015-6136HIGH The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrar | Dec 9, 2015 | 9.3 | 35 | NO | NO |
CVE-2015-0032HIGH vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a den | Mar 11, 2015 | 9.3 | 33 | NO | NO |
CVE-2015-2372HIGH vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a den | Jul 14, 2015 | 9.3 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
1 CVE
4.3% of CVEs· 97th percentile
Metasploit
1 CVE
4.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Vbscript
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.8 | 20 | 7.5 | 25.7% | 1 | 3 |
| 5.7 | 18 | 7.4 | 29.6% | 1 | 3 |
| 5.6 | 10 | 7.8 | 24.2% | 0 | 2 |