CVE-2011-2382

Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
microsoftinternet_explorer
𝑥
≤ 8
microsoftinternet_explorer
3.0
microsoftinternet_explorer
3.0.1
microsoftinternet_explorer
3.0.2
microsoftinternet_explorer
3.1
microsoftinternet_explorer
3.2
microsoftinternet_explorer
4.0
microsoftinternet_explorer
4.0.1
microsoftinternet_explorer
4.0.1:sp1
microsoftinternet_explorer
4.0.1:sp2
microsoftinternet_explorer
4.01
microsoftinternet_explorer
4.1
microsoftinternet_explorer
4.01:sp1
microsoftinternet_explorer
4.5
microsoftinternet_explorer
4.40.308
microsoftinternet_explorer
4.40.520
microsoftinternet_explorer
4.70.1155
microsoftinternet_explorer
4.70.1158
microsoftinternet_explorer
4.70.1215
microsoftinternet_explorer
4.70.1300
microsoftinternet_explorer
4.71.544
microsoftinternet_explorer
4.71.1008.3
microsoftinternet_explorer
4.71.1712.6
microsoftinternet_explorer
4.72.2106.8
microsoftinternet_explorer
4.72.3110.8
microsoftinternet_explorer
4.72.3612.1713
microsoftinternet_explorer
5.0
microsoftinternet_explorer
5.0.1
microsoftinternet_explorer
5.0.1:sp1
microsoftinternet_explorer
5.0.1:sp2
microsoftinternet_explorer
5.0.1:sp3
microsoftinternet_explorer
5.0.1:sp4
microsoftinternet_explorer
5.00.0518.10
microsoftinternet_explorer
5.00.0910.1309
microsoftinternet_explorer
5.00.2014.0216
microsoftinternet_explorer
5.00.2314.1003
microsoftinternet_explorer
5.00.2516.1900
microsoftinternet_explorer
5.00.2614.3500
microsoftinternet_explorer
5.00.2919.800
microsoftinternet_explorer
5.00.2919.3800
microsoftinternet_explorer
5.00.2919.6307
microsoftinternet_explorer
5.00.2920.0000
microsoftinternet_explorer
5.00.3103.1000
microsoftinternet_explorer
5.00.3105.0106
microsoftinternet_explorer
5.00.3314.2101
microsoftinternet_explorer
5.00.3315.1000
microsoftinternet_explorer
5.00.3502.1000
microsoftinternet_explorer
5.00.3700.1000
microsoftinternet_explorer
5.01
microsoftinternet_explorer
5.1
microsoftinternet_explorer
5.01:sp1
microsoftinternet_explorer
5.01:sp2
microsoftinternet_explorer
5.01:sp3
microsoftinternet_explorer
5.01:sp4
microsoftinternet_explorer
5.2.3
microsoftinternet_explorer
5.5
microsoftinternet_explorer
5.5:preview
microsoftinternet_explorer
5.5:sp1
microsoftinternet_explorer
5.5:sp2
microsoftinternet_explorer
5.50.3825.1300
microsoftinternet_explorer
5.50.4030.2400
microsoftinternet_explorer
5.50.4134.0100
microsoftinternet_explorer
5.50.4134.0600
microsoftinternet_explorer
5.50.4308.2900
microsoftinternet_explorer
5.50.4522.1800
microsoftinternet_explorer
5.50.4807.2300
microsoftinternet_explorer
6.0
microsoftinternet_explorer
6.00.2462.0000
microsoftinternet_explorer
6.00.2479.0006
microsoftinternet_explorer
6.0.2600
microsoftinternet_explorer
6.00.2600.0000
microsoftinternet_explorer
6.0.2800
microsoftinternet_explorer
6.0.2800.1106
microsoftinternet_explorer
6.00.2800.1106
microsoftinternet_explorer
6.0.2900
microsoftinternet_explorer
6.0.2900.2180
microsoftinternet_explorer
6.00.2900.2180
microsoftinternet_explorer
6.00.3663.0000
microsoftinternet_explorer
6.00.3718.0000
microsoftinternet_explorer
6.00.3790.0000
microsoftinternet_explorer
6.00.3790.1830
microsoftinternet_explorer
6.00.3790.3959
microsoftinternet_explorer
7.0
microsoftinternet_explorer
7.0:beta
microsoftinternet_explorer
7.0:beta1
microsoftinternet_explorer
7.0:beta2
microsoftinternet_explorer
7.0:beta3
microsoftinternet_explorer
7.0.5730:unknown
microsoftinternet_explorer
7.0.5730.11
microsoftinternet_explorer
7.00.5730.1100
microsoftinternet_explorer
7.00.6000.16386
microsoftinternet_explorer
7.00.6000.16441
𝑥
= Vulnerable software versions