CVE-2016-3291 Information
Feb 14, 2021
cve
Description
Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests which allows remote attackers to obtain sensitive information via a crafted web site aka \Microsoft Browser Information Disclosure Vulnerability.\
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Reference
http://www.securityfocus.com/bid/92834 http://www.securitytracker.com/id/1036788 http://www.securitytracker.com/id/1036789 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
2.4
Share on: