9.3

CVE-2010-0555

Exploit

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka the URLMON sniffing vulnerability, a variant of CVE-2009-1140 and related to CVE-2008-1448.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows Server 2003 Updatesp1 Editionitanium
MicrosoftWindows Xp Editionpro_x64
MicrosoftWindows Xp Updatesp2
MicrosoftWindows Xp Updatesp2 Editionpro_x64
MicrosoftWindows Xp Updatesp3
MicrosoftWindows Server 2003 Updatesp1 Editionitanium
MicrosoftWindows Server 2008 Edition32_bit
MicrosoftWindows Server 2008 Editionitanium
MicrosoftWindows Vista Editionx64
MicrosoftWindows Vista Updatesp1
MicrosoftWindows Vista Versiongold
MicrosoftWindows Xp Editionx64
MicrosoftWindows Xp Updatesp2
MicrosoftWindows Xp Updatesp2 Editionx64
MicrosoftWindows Xp Updatesp3
MicrosoftInternet Explorer Version5.01 Updatesp4
MicrosoftInternet Explorer Version6 Updatesp1
MicrosoftWindows 2000 Updatesp4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 31.39% 0.966
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C