CVE-2016-3273

Published on: 07/12/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:03 PM UTC

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Certain versions of Edge from Microsoft contain the following vulnerability:

The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

  • CVE-2016-3273 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.3 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK HIGH NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH NONE NONE

CVSS2 Score: 2.6 - LOW

Access
Vector
Access
Complexity
Authentication
NETWORK HIGH NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL NONE NONE

CVE References

Description Tags Link
Microsoft Security Bulletin MS16-084 - Critical | Microsoft Docs docs.microsoft.com
text/html
URL Logo MS MS16-084
Malformed Request cve.report (archive)
text/html
URL Logo BID 91576
Microsoft Security Bulletin MS16-085 - Critical | Microsoft Docs docs.microsoft.com
text/html
URL Logo MS MS16-085
Microsoft Internet Explorer Multiple Bugs Let Remote Users Spoof Web Content, Bypass Security Restrictions, Conduct Cross-Site Scripting Attacks, and Execute Arbitrary Code - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1036283

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMicrosoftEdgeAllAllAllAll
ApplicationMicrosoftEdgeAllAllAllAll
ApplicationMicrosoftInternet Explorer10AllAllAll
ApplicationMicrosoftInternet Explorer11AllAllAll
ApplicationMicrosoftInternet Explorer9AllAllAll
ApplicationMicrosoftInternet Explorer10AllAllAll
ApplicationMicrosoftInternet Explorer11AllAllAll
ApplicationMicrosoftInternet Explorer9AllAllAll
  • cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*: