CVE Vulnerabilities

CVE-2008-3475

Use of Uninitialized Resource

Published: Oct 15, 2008 | Modified: Feb 08, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka Uninitialized Memory Corruption Vulnerability.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Internet_explorer Microsoft 5.01-sp4 (including) 5.01-sp4 (including)
Internet_explorer Microsoft 6-sp1 (including) 6-sp1 (including)

Potential Mitigations

References