CVE-2015-6138: XSS
Published Dec 9, 2015
·Updated
Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerability."
Affected Software
4 affected components
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Dec 9, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6138?
CVE-2015-6138 is considered to have a critical severity rating due to its ability to bypass XSS protection mechanisms in Internet Explorer.
2
How do I fix CVE-2015-6138?
To fix CVE-2015-6138, users should update their Internet Explorer to the latest version available from Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2015-6138?
CVE-2015-6138 affects Internet Explorer versions 8 through 11.
4
What type of vulnerability is CVE-2015-6138?
CVE-2015-6138 is a cross-site scripting (XSS) filter bypass vulnerability.
5
Can CVE-2015-6138 allow remote attacks?
Yes, CVE-2015-6138 could allow remote attackers to exploit the vulnerability via specific methods.