4.3
CVE-2008-4033
- EPSS 27.75%
- Veröffentlicht 12.11.2008 23:30:02
- Zuletzt bearbeitet 16.06.2026 22:57:01
- Erkennungen
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Xml Core Services Version 4.0
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows 7
Microsoft ≫ Windows 7 Update sp1
Microsoft ≫ Windows Server 2008 Update sp2
Microsoft ≫ Windows Server 2008 Version -
Microsoft ≫ Windows Server 2008 Version r2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows 7
Microsoft ≫ Windows 7 Update sp1
Microsoft ≫ Windows Server 2008 Update sp2
Microsoft ≫ Windows Server 2008 Version -
Microsoft ≫ Windows Server 2008 Version r2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Xml Core Services Version 3.0
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows Server 2008 Version -
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows Server 2008 Version -
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Xml Core Services Version 6.0
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows Server 2008 Version -
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Xp Update sp2 HwPlatform x64
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows Server 2008 Version -
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Xp Update sp2 HwPlatform x64
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Xml Core Services Version 5.0
Microsoft ≫ Expression Web
Microsoft ≫ Expression Web Version 2
Microsoft ≫ Groove Version 2007
Microsoft ≫ Office Version 2003 Update sp3
Microsoft ≫ Office Version 2007 Update sp1
Microsoft ≫ Office Compatibility Pack
Microsoft ≫ Office Compatibility Pack Update sp1
Microsoft ≫ Office Word Viewer Version 2003 Update sp3
Microsoft ≫ Sharepoint Server Version 2007
Microsoft ≫ Sharepoint Server Version 2007 Update sp1
Microsoft ≫ Expression Web Version 2
Microsoft ≫ Groove Version 2007
Microsoft ≫ Office Version 2003 Update sp3
Microsoft ≫ Office Version 2007 Update sp1
Microsoft ≫ Office Compatibility Pack
Microsoft ≫ Office Compatibility Pack Update sp1
Microsoft ≫ Office Word Viewer Version 2003 Update sp3
Microsoft ≫ Sharepoint Server Version 2007
Microsoft ≫ Sharepoint Server Version 2007 Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 27.75% | 0.978 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://marc.info/?l=bugtraq&m=122703006921213&w=2
http://securitytracker.com/id?1021164
http://www.us-cert.gov/cas/techalerts/TA08-316A.html
http://www.vupen.com/english/advisories/2008/3111
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069
http://www.securityfocus.com/bid/32204
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847