9.3

CVE-2008-4261

Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftInternet Explorer Version5.01 Updatesp4
   MicrosoftWindows 2000 Updatesp4
MicrosoftInternet Explorer Version6
   MicrosoftWindows Server 2003 Updatesp1
   MicrosoftWindows Server 2003 Updatesp1 Editionitanium
   MicrosoftWindows Server 2003 Updatesp1 Editionx64
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Xp Updategold Editionprofessional_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
   MicrosoftWindows Xp Updatesp3
MicrosoftInternet Explorer Version6 Updatesp1
   MicrosoftWindows 2000 Updatesp4
MicrosoftInternet Explorer Version7
   MicrosoftWindows Server 2003 Updatesp1
   MicrosoftWindows Server 2003 Updatesp1 Editionitanium
   MicrosoftWindows Server 2003 Updatesp1 Editionx64
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Server 2008 Editionitanium
   MicrosoftWindows Server 2008 Editionx32
   MicrosoftWindows Server 2008 Editionx64
   MicrosoftWindows Vista Updategold
   MicrosoftWindows Vista Updategold Editionx64
   MicrosoftWindows Vista Updatesp1
   MicrosoftWindows Xp Updategold Editionprofessional_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
   MicrosoftWindows Xp Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 64.44% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C