4.3
CVE-2010-1258
- EPSS 17%
- Veröffentlicht 11.08.2010 18:47:49
- Zuletzt bearbeitet 16.06.2026 23:17:58
- Erkennungen
Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handler Cross-Domain Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Edition itanium
Microsoft ≫ Windows Server 2008 Edition x32
Microsoft ≫ Windows Server 2008 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x32
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp1
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Edition itanium
Microsoft ≫ Windows Server 2008 Edition x32
Microsoft ≫ Windows Server 2008 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x32
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp1
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Internet Explorer Version 8
Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
Microsoft ≫ Windows 7
Microsoft ≫ Windows 7 Version -
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Edition itanium
Microsoft ≫ Windows Server 2008 Edition x32
Microsoft ≫ Windows Server 2008 Edition x64
Microsoft ≫ Windows Server 2008 Update r2 Edition itanium
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x32
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp1
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows 7
Microsoft ≫ Windows 7 Version -
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Edition itanium
Microsoft ≫ Windows Server 2008 Edition x32
Microsoft ≫ Windows Server 2008 Edition x64
Microsoft ≫ Windows Server 2008 Update r2 Edition itanium
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x32
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp1
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 17% | 0.967 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.us-cert.gov/cas/techalerts/TA10-222A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-053
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11954