CVE Vulnerabilities

CVE-2008-3475

Use of Uninitialized Resource

Published: Oct 15, 2008 | Modified: Apr 09, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka Uninitialized Memory Corruption Vulnerability.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
Internet_explorerMicrosoft5.01-sp4 (including)5.01-sp4 (including)
Internet_explorerMicrosoft6-sp1 (including)6-sp1 (including)

Potential Mitigations

References