CVE-2011-1245Sensitive Information Exposure in Microsoft Internet Explorer

Severity
4.3MEDIUMNVD
EPSS
21.1%
top 4.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateJun 14

Description

Microsoft Internet Explorer 6 and 7 does not properly restrict script access to content from a (1) different domain or (2) different zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Javascript Information Disclosure Vulnerability."

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-x8q2-c58h-jr22: Microsoft Internet Explorer 6 and 7 does not properly restrict script access to content from a (1) different domain or (2) different zone, which allow2022-05-13

📋Vendor Advisories

1
Microsoft
Chromium: CVE-2022-2011 Use after free in ANGLE2022-06-14

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 04-12-2011
CVE-2011-1245 — Sensitive Information Exposure | cvebase