CVE-2008-3475
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 39.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 39.86% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- microsoft/internet explorer
- Source
- secure@microsoft.com
References
- http://ifsec.blogspot.com/2008/10/internet-explorer-6-componentfrompoint.htmlIssue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=122479227205998&w=2Mailing List
- http://www.securityfocus.com/archive/1/497380/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31617Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021047Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-288A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/2809Broken Link
- http://www.zerodayinitiative.com/advisories/ZDI-08-069/Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-058Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45563Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45565Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13151Broken Link
- http://ifsec.blogspot.com/2008/10/internet-explorer-6-componentfrompoint.htmlIssue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=122479227205998&w=2Mailing List
- http://www.securityfocus.com/archive/1/497380/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31617Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021047Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-288A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/2809Broken Link
- http://www.zerodayinitiative.com/advisories/ZDI-08-069/Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-058Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45563Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45565Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13151Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.