9.3

CVE-2008-3475

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 5.01 Update sp4
   Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Internet Explorer Version 6 Update sp1
   Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Internet Explorer Version 6 Update -
   Microsoft ≫ Windows Server 2003 Version - HwPlatform x64
   Microsoft ≫ Windows Server 2003 Version - Update sp1
   Microsoft ≫ Windows Server 2003 Version - Update sp1 SwEdition - HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2
   Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform x64
   Microsoft ≫ Windows Xp Version - SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Internet Explorer Version 7.0
   Microsoft ≫ Windows Server 2003 Version - HwPlatform x64
   Microsoft ≫ Windows Server 2003 Version - Update sp1
   Microsoft ≫ Windows Server 2003 Version - Update sp1 SwEdition - HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2
   Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform x64
   Microsoft ≫ Windows Server 2008 Version -
   Microsoft ≫ Windows Vista Version -
   Microsoft ≫ Windows Vista Version - Update sp1
   Microsoft ≫ Windows Xp Version - SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 39.86% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

http://marc.info/?l=bugtraq&m=122479227205998&w=2
Mailing List
http://www.us-cert.gov/cas/techalerts/TA08-288A.html
Third Party Advisory
US Government Resource
Broken Link
http://www.vupen.com/english/advisories/2008/2809
Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-058
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/45565
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1021047
Third Party Advisory
Broken Link
VDB Entry
http://ifsec.blogspot.com/2008/10/internet-explorer-6-componentfrompoint.html
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/archive/1/497380/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/31617
Patch
Third Party Advisory
Broken Link
VDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-08-069/
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45563
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13151
Broken Link