CVE-2016-3351

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:49

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/92788 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92788 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1036788 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1036788 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1036789 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1036789 - Broken Link, Third Party Advisory, VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - Patch, Vendor Advisory () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - Patch, Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - Patch, Vendor Advisory () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - Patch, Vendor Advisory
References () https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - Exploit () https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - Exploit

02 Jul 2024, 12:23

Type Values Removed Values Added
First Time Microsoft windows Server 2012
Microsoft windows 10 1511
Microsoft windows Vista
Microsoft windows 10 1507
Microsoft windows Server 2008
Microsoft windows Rt 8.1
Microsoft windows 7
Microsoft windows 8.1
Microsoft windows 10 1607
CVSS v2 : 2.6
v3 : 3.1
v2 : 2.6
v3 : 6.5
CPE cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
References () http://www.securityfocus.com/bid/92788 - () http://www.securityfocus.com/bid/92788 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1036788 - () http://www.securitytracker.com/id/1036788 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1036789 - () http://www.securitytracker.com/id/1036789 - Broken Link, Third Party Advisory, VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - Patch, Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - Patch, Vendor Advisory
References () https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - () https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - Exploit
CWE CWE-200 NVD-CWE-noinfo

Information

Published : 2016-09-14 10:59

Updated : 2024-11-21 02:49


NVD link : CVE-2016-3351

Mitre link : CVE-2016-3351

CVE.ORG link : CVE-2016-3351


JSON object : View

Products Affected

microsoft

  • windows_10_1511
  • windows_vista
  • windows_10_1507
  • windows_7
  • windows_8.1
  • edge
  • windows_rt_8.1
  • windows_10_1607
  • windows_server_2012
  • windows_server_2008
  • internet_explorer