Vulnerabilities > Microsoft > Internet Explorer > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-03-05 CVE-2019-0676 Unspecified vulnerability in Microsoft Internet Explorer 10/11
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
network
microsoft
4.3
2019-03-05 CVE-2019-0654 Unspecified vulnerability in Microsoft Edge and Internet Explorer
A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'.
network
microsoft
4.3
2018-11-06 CVE-2018-18966 Unspecified vulnerability in Oscommerce Online Merchant 2.3.4.1
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
network
low complexity
oscommerce microsoft
4.0
2018-09-14 CVE-2018-17039 Cross-site Scripting vulnerability in 1234N Minicms 1.10
MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
4.3
2018-09-13 CVE-2018-8470 Cross-site Scripting vulnerability in Microsoft Internet Explorer 11
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
network
microsoft CWE-79
4.3
2018-09-13 CVE-2018-8452 Information Exposure vulnerability in Microsoft Chakracore, Edge and Internet Explorer
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.
network
microsoft CWE-200
4.3
2018-09-13 CVE-2018-8315 Information Exposure vulnerability in Microsoft Chakracore, Edge and Internet Explorer
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
network
high complexity
microsoft CWE-200
4.0
2018-08-15 CVE-2018-8357 Unspecified vulnerability in Microsoft Edge and Internet Explorer
An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege Vulnerability." This affects Internet Explorer 11, Microsoft Edge.
network
high complexity
microsoft
5.1
2018-08-15 CVE-2018-8351 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Microsoft Edge and Internet Explorer
An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
network
microsoft CWE-829
4.3
2018-07-11 CVE-2018-0949 Unspecified vulnerability in Microsoft Internet Explorer 10/11/9
A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
network
microsoft
4.3