Back
CVE-2008-3475
HIGH
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."
Published: Oct 15, 2008
Modified: Apr 23, 2026
CWE-908
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | 5.01 |
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 7.0 |
GitHub Security Advisory GHSA-hj95-cvvq-rc83
Microsoft Internet Explorer 6 does not properly handle errors related to using the...
References (24)
- http://ifsec.blogspot.com/2008/10/internet-explorer-6-componentfrompoint.html Issue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=122479227205998&w=2 Mailing List
- http://www.securityfocus.com/archive/1/497380/100/0/threaded Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31617 Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021047 Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-288A.html Broken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/2809 Broken Link
- http://www.zerodayinitiative.com/advisories/ZDI-08-069/ Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-058 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45563 Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45565 Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13151 Broken Link
- http://ifsec.blogspot.com/2008/10/internet-explorer-6-componentfrompoint.html Issue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=122479227205998&w=2 Mailing List
- http://www.securityfocus.com/archive/1/497380/100/0/threaded Broken Link, Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
8.8 / 10
EPSS Score
59.20%
Top 2% most likely to be exploited
Threat Score
53 / 100
Data Sources
NVD
EPSS
GitHub