4.3

CVE-2008-4033

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftXml Core Services Version4.0
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows 2003 Server Updatesp1
   MicrosoftWindows 2003 Server Updatesp2
   MicrosoftWindows 7
   MicrosoftWindows 7 Updatesp1
   MicrosoftWindows Server 2008 Updatesp2
   MicrosoftWindows Server 2008 Version-
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2008 Versionr2 Updatesp1
   MicrosoftWindows Vista Updatesp1
   MicrosoftWindows Vista Updatesp2
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp3
MicrosoftXml Core Services Version3.0
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows 2003 Server Updatesp1
   MicrosoftWindows 2003 Server Updatesp2
   MicrosoftWindows Server 2008 Version-
   MicrosoftWindows Vista Updatesp1
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp3
MicrosoftXml Core Services Version6.0
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows 2003 Server Updatesp1
   MicrosoftWindows 2003 Server Updatesp2
   MicrosoftWindows Server 2008 Version-
   MicrosoftWindows Vista Updatesp1
   MicrosoftWindows Xp Updatesp2 HwPlatformx64
   MicrosoftWindows Xp Updatesp3
MicrosoftXml Core Services Version5.0
   MicrosoftExpression Web
   MicrosoftExpression Web Version2
   MicrosoftGroove Version2007
   MicrosoftOffice Version2003 Updatesp3
   MicrosoftOffice Version2007 Updatesp1
   MicrosoftOffice Compatibility Pack
   MicrosoftOffice Compatibility Pack Updatesp1
   MicrosoftOffice Word Viewer Version2003 Updatesp3
   MicrosoftSharepoint Server Version2007
   MicrosoftSharepoint Server Version2007 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 62.58% 0.983
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.