← Back to browse · API

CVE-2016-0189

Severity
HIGH
CVSS
7.5
EPSS
0.93711
Risk score
57.8
CISA KEV
Yes
PoC
No
Published
2016-05-11
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2016-0226, GHSA-QW68-VQP7-FF9R
Products
Microsoft:Internet Explorer, n/a:n/a n/a
Sources
cisa.gov CVE-2016-0189
euvd EUVD-2016-0226

Description

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

References