9.3

CVE-2008-3472

Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftInternet Explorer Version5.01 Updatesp4
   MicrosoftWindows 2000 Updatesp4
MicrosoftInternet Explorer Version6
   MicrosoftWindows Server 2003 Updatesp1
   MicrosoftWindows Server 2003 Updatesp1 Editionitanium
   MicrosoftWindows Server 2003 Updatesp1 Editionx64
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Xp Updategold Editionprofessional_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
   MicrosoftWindows Xp Updatesp3
MicrosoftInternet Explorer Version6 Updatesp1
   MicrosoftWindows 2000 Updatesp4
MicrosoftInternet Explorer Version7
   MicrosoftWindows Server 2003 Updatesp1
   MicrosoftWindows Server 2003 Updatesp1 Editionitanium
   MicrosoftWindows Server 2003 Updatesp1 Editionx64
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Server 2008 Editionitanium
   MicrosoftWindows Server 2008 Editionx32
   MicrosoftWindows Server 2008 Editionx64
   MicrosoftWindows Vista Updategold
   MicrosoftWindows Vista Updategold Editionx64
   MicrosoftWindows Vista Updatesp1
   MicrosoftWindows Xp Updategold Editionprofessional_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
   MicrosoftWindows Xp Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 46.05% 0.976
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C