CVE-2008-3475

8.8
HIGHCVSS v3.1 Base Score
39.86%
MEDIUM RiskEPSS (99th percentile)

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."

Published: 10/15/2008
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

9.3

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

39.86%MEDIUM Exploitation Risk
99th percentile

This vulnerability has a 39.86% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

Advertisement