Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2016-3325Sensitive Information Exposure in Microsoft Internet Explorer

Severity
3.1LOWNVD
EPSS
24.3%
top 3.89%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 14
Latest updateMay 14

Description

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-5v8f-79h7-hmp4: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browse2022-05-14
CVEList
CVE-2016-3325: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browse2016-09-14

💥Exploits & PoCs

1
Exploit-DB
Microsoft WININET.dll - 'CHttp­Header­Parser::Parse­Status­Line' Out-of-Bounds Read (MS16-104/MS16-105)2016-11-10

📋Vendor Advisories

1
Microsoft
Internet Explorer Information Disclosure Vulnerability2016-09-13
CVE-2016-3325 — Sensitive Information Exposure | cvebase