CVE-2008-3475: Critical severity internet explorer vulnerability
Published Oct 15, 2008
·Updated
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."
Affected Software
48 affected components
All of the following
Any of the following
Microsoft Internet Explorer=5.01-sp4
Microsoft Internet Explorer=6-sp1
Microsoft Windows 2000=sp4
All of the following
Microsoft Internet Explorer=6
Any of the following
Microsoft Windows Server 2003
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows XP
Microsoft Windows XP=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
All of the following
Microsoft Internet Explorer=7.0
Any of the following
Microsoft Windows Server 2003
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows Vista=sp1
Microsoft Windows XP
Microsoft Windows XP=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Internet Explorer=5.01-sp4
Microsoft Windows 2000=sp4
Microsoft Internet Explorer=6
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=gold
Microsoft Windows XP=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Internet Explorer=6-sp1
Microsoft Internet Explorer=7
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows Vista=gold
Microsoft Windows Vista=gold
Microsoft Windows Vista=sp1
Microsoft Windows Vista=sp1
Remediation
Patch Available
Event History
Oct 15, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
12:12 AM
DescriptionWeaknessAffected Software