9.3

CVE-2008-3473

Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftInternet Explorer Version5.01 Updatesp4
   MicrosoftWindows 2000 Version- Updatesp4
MicrosoftInternet Explorer Version6
   MicrosoftWindows Server 2003 Version- Updatesp1
   MicrosoftWindows Server 2003 Version- Updatesp1 HwPlatformitanium
   MicrosoftWindows Server 2003 Version- Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2003 Version- Updatesp2
   MicrosoftWindows Xp Version- Updategold SwEditionprofessional HwPlatformx64
   MicrosoftWindows Xp Version- Updatesp2
   MicrosoftWindows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
   MicrosoftWindows Xp Version- Updatesp3
MicrosoftInternet Explorer Version6 Updatesp1
   MicrosoftWindows 2000 Version- Updatesp4
MicrosoftInternet Explorer Version7
   MicrosoftWindows Server 2003 Version- Updatesp1
   MicrosoftWindows Server 2003 Version- Updatesp1 HwPlatformitanium
   MicrosoftWindows Server 2003 Version- Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2003 Version- Updatesp2
   MicrosoftWindows Server 2008 Version- HwPlatformitanium
   MicrosoftWindows Server 2008 Version- Editionx64
   MicrosoftWindows Server 2008 Version- Editionx86
   MicrosoftWindows Vista Version- Updategold
   MicrosoftWindows Vista Version- Updategold HwPlatformx64
   MicrosoftWindows Vista Version- Updatesp1
   MicrosoftWindows Vista Version- Updatesp1 HwPlatformx64
   MicrosoftWindows Xp Version- Updategold SwEditionprofessional HwPlatformx64
   MicrosoftWindows Xp Version- Updatesp2
   MicrosoftWindows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
   MicrosoftWindows Xp Version- Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 47.04% 0.976
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C