CVE-2006-3640
Summary
| CVE | CVE-2006-3640 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-09 00:04:00 UTC |
| Updated | 2021-07-23 12:18:00 UTC |
| Description | Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited web pages in other domains or zones, aka "Window Location Information Disclosure Vulnerability." |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Ie | 5.01 | All | All | All |
| Application | Microsoft | Ie | 6 | windows_server_2003_sp1 | All | All |
| Application | Microsoft | Ie | 5.01 | All | All | All |
| Application | Microsoft | Ie | 6 | windows_server_2003_sp1 | All | All |
| Application | Microsoft | Internet Explorer | 5.01 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Internet Explorer Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Microsoft Security Bulletin MS06-042 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Microsoft Internet Explorer Window Location Cross-Domain Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| SecurityTracker.com Archives - Microsoft Internet Explorer Bugs Let Remote Users Obtain Information or Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| 27850 | OSVDB | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.