Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2010-3342 (GCVE-0-2010-3342)
Vulnerability from cvelistv5 – Published: 2010-12-16 19:00 – Updated: 2024-08-07 03:03- n/a
| URL | Tags | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T03:03:19.105Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "MS10-090",
"tags": [
"vendor-advisory",
"x_refsource_MS",
"x_transferred"
],
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
},
{
"name": "oval:org.mitre.oval:def:11447",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
},
{
"name": "1024872",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id?1024872"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2010-12-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-10-12T19:57:01.000Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "MS10-090",
"tags": [
"vendor-advisory",
"x_refsource_MS"
],
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
},
{
"name": "oval:org.mitre.oval:def:11447",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
},
{
"name": "1024872",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id?1024872"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "secure@microsoft.com",
"ID": "CVE-2010-3342",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "MS10-090",
"refsource": "MS",
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
},
{
"name": "oval:org.mitre.oval:def:11447",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
},
{
"name": "1024872",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id?1024872"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2010-3342",
"datePublished": "2010-12-16T19:00:00.000Z",
"dateReserved": "2010-09-14T00:00:00.000Z",
"dateUpdated": "2024-08-07T03:03:19.105Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
GSD-2010-3342
Vulnerability from gsd - Updated: 2023-12-13 01:21{
"GSD": {
"alias": "CVE-2010-3342",
"description": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348.",
"id": "GSD-2010-3342"
},
"gsd": {
"metadata": {
"exploitCode": "unknown",
"remediation": "unknown",
"reportConfidence": "confirmed",
"type": "vulnerability"
},
"osvSchema": {
"aliases": [
"CVE-2010-3342"
],
"details": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348.",
"id": "GSD-2010-3342",
"modified": "2023-12-13T01:21:34.980252Z",
"schema_version": "1.4.0"
}
},
"namespaces": {
"cve.org": {
"CVE_data_meta": {
"ASSIGNER": "secure@microsoft.com",
"ID": "CVE-2010-3342",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "MS10-090",
"refsource": "MS",
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
},
{
"name": "oval:org.mitre.oval:def:11447",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
},
{
"name": "1024872",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id?1024872"
}
]
}
},
"nvd.nist.gov": {
"configurations": {
"CVE_data_version": "4.0",
"nodes": [
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*",
"cpe_name": [],
"vulnerable": false
},
{
"cpe23Uri": "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
}
]
},
"cve": {
"CVE_data_meta": {
"ASSIGNER": "secure@microsoft.com",
"ID": "CVE-2010-3342"
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "1024872",
"refsource": "SECTRACK",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securitytracker.com/id?1024872"
},
{
"name": "oval:org.mitre.oval:def:11447",
"refsource": "OVAL",
"tags": [
"Tool Signature"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
},
{
"name": "MS10-090",
"refsource": "MS",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
}
]
}
},
"impact": {
"baseMetricV2": {
"cvssV2": {
"accessComplexity": "MEDIUM",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"version": "2.0"
},
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"severity": "MEDIUM",
"userInteractionRequired": true
}
},
"lastModifiedDate": "2022-02-28T19:19Z",
"publishedDate": "2010-12-16T19:33Z"
}
}
}
FKIE_CVE-2010-3342
Vulnerability from fkie_nvd - Published: 2010-12-16 19:33 - Updated: 2025-04-11 00:51| URL | Tags | ||
|---|---|---|---|
| secure@microsoft.com | http://www.securitytracker.com/id?1024872 | Broken Link, Third Party Advisory, VDB Entry | |
| secure@microsoft.com | https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090 | Patch, Vendor Advisory | |
| secure@microsoft.com | https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447 | Tool Signature | |
| af854a3a-2127-422b-91ae-364da2661108 | http://www.securitytracker.com/id?1024872 | Broken Link, Third Party Advisory, VDB Entry | |
| af854a3a-2127-422b-91ae-364da2661108 | https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090 | Patch, Vendor Advisory | |
| af854a3a-2127-422b-91ae-364da2661108 | https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447 | Tool Signature |
| Vendor | Product | Version | |
|---|---|---|---|
| microsoft | internet_explorer | 6 | |
| microsoft | windows_xp | - | |
| microsoft | windows_xp | - | |
| microsoft | internet_explorer | 7 | |
| microsoft | windows_vista | - | |
| microsoft | windows_vista | - | |
| microsoft | windows_xp | - | |
| microsoft | windows_xp | - | |
| microsoft | internet_explorer | 8 | |
| microsoft | windows_7 | - | |
| microsoft | windows_vista | - | |
| microsoft | windows_vista | - | |
| microsoft | windows_xp | - | |
| microsoft | windows_xp | - |
{
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*",
"matchCriteriaId": "693D3C1C-E3E4-49DB-9A13-44ADDFF82507",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*",
"matchCriteriaId": "C6109348-BC79-4ED3-8D41-EA546A540C79",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*",
"matchCriteriaId": "C9392D35-7BF5-48E9-879B-BBDE9A9E9AB9",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*",
"matchCriteriaId": "1A33FA7F-BB2A-4C66-B608-72997A2BD1DB",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*",
"matchCriteriaId": "3A04E39A-623E-45CA-A5FC-25DAA0F275A3",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*",
"matchCriteriaId": "BF1AD1A1-EE20-4BCE-9EE6-84B27139811C",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*",
"matchCriteriaId": "C6109348-BC79-4ED3-8D41-EA546A540C79",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*",
"matchCriteriaId": "C9392D35-7BF5-48E9-879B-BBDE9A9E9AB9",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*",
"matchCriteriaId": "A52E757F-9B41-43B4-9D67-3FEDACA71283",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E33796DB-4523-4F04-B564-ADF030553D51",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*",
"matchCriteriaId": "3A04E39A-623E-45CA-A5FC-25DAA0F275A3",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*",
"matchCriteriaId": "BF1AD1A1-EE20-4BCE-9EE6-84B27139811C",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*",
"matchCriteriaId": "C6109348-BC79-4ED3-8D41-EA546A540C79",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*",
"matchCriteriaId": "C9392D35-7BF5-48E9-879B-BBDE9A9E9AB9",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348."
},
{
"lang": "es",
"value": "Microsoft Internet Explorer 6, 7 y 8 no previene el renderizado del contenido cacheado como HTML, lo que permite a atacantes remotos acceder al contenido a trav\u00e9s de un (1)dominio distinto o (2) zona diferente a trav\u00e9s de una secuencia de comandos no especificada. Tambi\u00e9n conocida como \"Cross-Domain Information Disclosure Vulnerability\". Vulnerabilidad distinta de CVE-2010-3348."
}
],
"id": "CVE-2010-3342",
"lastModified": "2025-04-11T00:51:21.963",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "MEDIUM",
"cvssData": {
"accessComplexity": "MEDIUM",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"version": "2.0"
},
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": true
}
]
},
"published": "2010-12-16T19:33:02.380",
"references": [
{
"source": "secure@microsoft.com",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securitytracker.com/id?1024872"
},
{
"source": "secure@microsoft.com",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
},
{
"source": "secure@microsoft.com",
"tags": [
"Tool Signature"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securitytracker.com/id?1024872"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Tool Signature"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
CERTA-2010-AVI-593
Vulnerability from certfr_avis - Published: 2010-12-15 - Updated: 2010-12-15
Plusieurs vulnérabilités dans Internet Explorer permettent l'exécution de code arbitraire à distance ou des fuites de données.
Description
Plusieurs vulnérabilités dans Internet Explorer permettent l'exécution de code arbitraire à distance ou des fuites de données, notamment des erreurs de traitement des objets et éléments HTML permettent l'exécution de code arbitraire à distance.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
None| Vendor | Product | Description | ||
|---|---|---|---|---|
| Microsoft | Windows | Internet Explorer 6 sur Windows Server 2003 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2003 x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Vista SP1 et SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2008 x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 6 sur Windows Server 2003 x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 6 sur Windows XP SP3 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Server 2008 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 6 sur Windows XP x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 6 sur Windows Server 2003 Itanium SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Server 2003 x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows XP SP3 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2003 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2008 Itanium ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2008 Itanium SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Server 2008 x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Vista x64 SP1 et SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2008 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Server 2008 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Vista x64 SP1 et SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows 7 32 bits et 64 bits ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2003 Itanium SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows XP SP3 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows XP x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2008 x64 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Server 2003 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Vista SP1 et SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Server 2008 r2 x64 et Itanium. | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows XP x64 SP2 ; | ||
| Microsoft | Windows | Internet Explorer 8 sur Windows Server 2008 x64 ; | ||
| Microsoft | Windows | Internet Explorer 7 sur Windows Server 2008 ; |
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Internet Explorer 6 sur Windows Server 2003 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2003 x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Vista SP1 et SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2008 x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 6 sur Windows Server 2003 x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 6 sur Windows XP SP3 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Server 2008 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 6 sur Windows XP x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 6 sur Windows Server 2003 Itanium SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Server 2003 x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows XP SP3 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2003 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2008 Itanium ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2008 Itanium SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Server 2008 x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Vista x64 SP1 et SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2008 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Server 2008 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Vista x64 SP1 et SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows 7 32 bits et 64 bits ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2003 Itanium SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows XP SP3 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows XP x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2008 x64 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Server 2003 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Vista SP1 et SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Server 2008 r2 x64 et Itanium.",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows XP x64 SP2 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 8 sur Windows Server 2008 x64 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
},
{
"description": "Internet Explorer 7 sur Windows Server 2008 ;",
"product": {
"name": "Windows",
"vendor": {
"name": "Microsoft",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Description\n\nPlusieurs vuln\u00e9rabilit\u00e9s dans Internet Explorer permettent l\u0027ex\u00e9cution\nde code arbitraire \u00e0 distance ou des fuites de donn\u00e9es, notamment des\nerreurs de traitement des objets et \u00e9l\u00e9ments HTML permettent l\u0027ex\u00e9cution\nde code arbitraire \u00e0 distance.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [
{
"name": "CVE-2010-3348",
"url": "https://www.cve.org/CVERecord?id=CVE-2010-3348"
},
{
"name": "CVE-2010-3340",
"url": "https://www.cve.org/CVERecord?id=CVE-2010-3340"
},
{
"name": "CVE-2010-3345",
"url": "https://www.cve.org/CVERecord?id=CVE-2010-3345"
},
{
"name": "CVE-2010-3346",
"url": "https://www.cve.org/CVERecord?id=CVE-2010-3346"
},
{
"name": "CVE-2010-3342",
"url": "https://www.cve.org/CVERecord?id=CVE-2010-3342"
},
{
"name": "CVE-2010-3343",
"url": "https://www.cve.org/CVERecord?id=CVE-2010-3343"
},
{
"name": "CVE-2010-3962",
"url": "https://www.cve.org/CVERecord?id=CVE-2010-3962"
}
],
"initial_release_date": "2010-12-15T00:00:00",
"last_revision_date": "2010-12-15T00:00:00",
"links": [],
"reference": "CERTA-2010-AVI-593",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2010-12-15T00:00:00.000000"
}
],
"risks": [
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
}
],
"summary": "Plusieurs vuln\u00e9rabilit\u00e9s dans Internet Explorer permettent l\u0027ex\u00e9cution\nde code arbitraire \u00e0 distance ou des fuites de donn\u00e9es.\n",
"title": "Vuln\u00e9rabilit\u00e9s dans Microsoft Internet Explorer",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Microsoft MS10-090 du 14 d\u00e9cembre 2010",
"url": "http://www.microsoft.com/technet/security/Bulletin/MS10-090.mspx"
}
]
}
JVNDB-2010-000063
Vulnerability from jvndb - Published: 2010-12-15 18:19 - Updated:2010-12-15 18:19{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000063.html",
"dc:date": "2010-12-15T18:19+09:00",
"dcterms:issued": "2010-12-15T18:19+09:00",
"dcterms:modified": "2010-12-15T18:19+09:00",
"description": "Microsoft Internet Explorer contains a vulnerability in handling specific character encoding which may result in a cross-site scripting attack.\r\n\r\nMicrosoft Internet Explorer contains a vulnerability in handling specific UTF-7 encoded characters, which may result in cross-site scripting.\r\n\r\nFor more information, refer to the information provided by Microsoft.\r\n\r\nTakeshi Terada and Yutaka Kokubu from Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000063.html",
"sec:cpe": [
{
"#text": "cpe:/a:microsoft:internet_explorer",
"@product": "Microsoft Internet Explorer",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_7",
"@product": "Microsoft Windows 7",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_vista",
"@product": "Microsoft Windows Vista",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_xp",
"@product": "Microsoft Windows XP",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "2.6",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
"sec:identifier": "JVNDB-2010-000063",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN30273074/index.html",
"@id": "JVN#30273074",
"@source": "JVN"
},
{
"#text": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3342",
"@id": "CVE-2010-3342",
"@source": "CVE"
},
{
"#text": "http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3342",
"@id": "CVE-2010-3342",
"@source": "NVD"
},
{
"#text": "http://secunia.com/advisories/42091",
"@id": "SA42091",
"@source": "SECUNIA"
},
{
"#text": "http://www.securityfocus.com/bid/45256",
"@id": "45256",
"@source": "BID"
},
{
"#text": "http://www.vupen.com/english/advisories/2010/3214",
"@id": "VUPEN/ADV-2010-3214",
"@source": "VUPEN"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Internet Explorer vulnerable to cross-site scripting"
}
JVNDB-2010-000062
Vulnerability from jvndb - Published: 2010-12-15 18:18 - Updated:2010-12-15 18:18| Type | URL | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000062.html",
"dc:date": "2010-12-15T18:18+09:00",
"dcterms:issued": "2010-12-15T18:18+09:00",
"dcterms:modified": "2010-12-15T18:18+09:00",
"description": "Microsoft Internet Explorer contains a cross-site scripting vulnerability due to the way file types are determined.\r\n\r\nMicrosoft Internet Explorer contains a vulnerability in handling Content-Type, which may result in cross-site scripting.\r\n\r\nFor more information, refer to the information provided by Microsoft. \r\n\r\nYoshinari Fukumoto of Rakuten, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000062.html",
"sec:cpe": [
{
"#text": "cpe:/a:microsoft:internet_explorer",
"@product": "Microsoft Internet Explorer",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_7",
"@product": "Microsoft Windows 7",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_vista",
"@product": "Microsoft Windows Vista",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_xp",
"@product": "Microsoft Windows XP",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
"sec:identifier": "JVNDB-2010-000062",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN62275332/index.html",
"@id": "JVN#62275332",
"@source": "JVN"
},
{
"#text": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3342",
"@id": "CVE-2010-3342",
"@source": "CVE"
},
{
"#text": "http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3342",
"@id": "CVE-2010-3342",
"@source": "NVD"
},
{
"#text": "http://secunia.com/advisories/42091",
"@id": "SA42091",
"@source": "SECUNIA"
},
{
"#text": "http://www.securityfocus.com/bid/45256",
"@id": "45256",
"@source": "BID"
},
{
"#text": "http://www.vupen.com/english/advisories/2010/3214",
"@id": "VUPEN/ADV-2010-3214",
"@source": "VUPEN"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Internet Explorer vulnerable to cross-site scripting"
}
JVNDB-2010-000064
Vulnerability from jvndb - Published: 2010-12-15 18:19 - Updated:2010-12-15 18:19| Type | URL | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000064.html",
"dc:date": "2010-12-15T18:19+09:00",
"dcterms:issued": "2010-12-15T18:19+09:00",
"dcterms:modified": "2010-12-15T18:19+09:00",
"description": "Microsoft Internet Explorer contains a vulnerability in handling specific character encoding which may result in a cross-site scripting attack.\r\n\r\nMicrosoft Internet Explorer contains a vulnerability in handling specific EUC-JP or Shift_JIS encoded characters, which may result in cross-site scripting.\r\n\r\nFor more information, refer to the information provided by Microsoft. \r\n\r\nNetAgent Co.,Ltd. and hoshikuzu|star_dust reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000064.html",
"sec:cpe": [
{
"#text": "cpe:/a:microsoft:internet_explorer",
"@product": "Microsoft Internet Explorer",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_7",
"@product": "Microsoft Windows 7",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_vista",
"@product": "Microsoft Windows Vista",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
},
{
"#text": "cpe:/o:microsoft:windows_xp",
"@product": "Microsoft Windows XP",
"@vendor": "Microsoft Corporation",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "2.6",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
"sec:identifier": "JVNDB-2010-000064",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN21120853/index.html",
"@id": "JVN#21120853",
"@source": "JVN"
},
{
"#text": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3342",
"@id": "CVE-2010-3342",
"@source": "CVE"
},
{
"#text": "http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3342",
"@id": "CVE-2010-3342",
"@source": "NVD"
},
{
"#text": "http://secunia.com/advisories/42091",
"@id": "SA42091",
"@source": "SECUNIA"
},
{
"#text": "http://www.securityfocus.com/bid/45256",
"@id": "45256 ",
"@source": "BID"
},
{
"#text": "http://www.vupen.com/english/advisories/2010/3214",
"@id": "VUPEN/ADV-2010-3214",
"@source": "VUPEN"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Internet Explorer vulnerable to cross-site scripting"
}
GHSA-4PXM-66Q6-PP94
Vulnerability from github – Published: 2022-05-13 01:03 – Updated: 2022-05-13 01:03Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3348.
{
"affected": [],
"aliases": [
"CVE-2010-3342"
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2010-12-16T19:33:00Z",
"severity": "MODERATE"
},
"details": "Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka \"Cross-Domain Information Disclosure Vulnerability,\" a different vulnerability than CVE-2010-3348.",
"id": "GHSA-4pxm-66q6-pp94",
"modified": "2022-05-13T01:03:30Z",
"published": "2022-05-13T01:03:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2010-3342"
},
{
"type": "WEB",
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090"
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11447"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id?1024872"
}
],
"schema_version": "1.4.0",
"severity": []
}
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.