Back

CVE-2008-3475

HIGH

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."

Published: Oct 15, 2008 Modified: Apr 23, 2026
CWE-908

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: REQUIRED Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
microsoft internet_explorer 5.01
microsoft internet_explorer 6
microsoft internet_explorer 6
microsoft internet_explorer 7.0

GitHub Security Advisory GHSA-hj95-cvvq-rc83

Microsoft Internet Explorer 6 does not properly handle errors related to using the...

Risk Scores

CVSS Score 8.8 / 10
EPSS Score 59.20%

Top 2% most likely to be exploited

Threat Score 53 / 100

Data Sources

NVD EPSS GitHub