CVE-2008-3475Use of Uninitialized Resource in Microsoft Internet Explorer

Severity
8.8HIGHNVD
EPSS
59.2%
top 1.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateMay 2

Description

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDmicrosoft/internet_explorer5.01, 6, 7.0+2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-hj95-cvvq-rc83: Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorre2022-05-02

📐Framework References

2
CWE
Improper Initialization
CWE
Use of Uninitialized Resource
CVE-2008-3475 — Use of Uninitialized Resource | cvebase