Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-2382


Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.


Published

2011-06-03T17:55:00.763

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft ie 9 Yes
Application microsoft internet_explorer ≤ 8 Yes
Application microsoft internet_explorer 3.0 Yes
Application microsoft internet_explorer 3.0.1 Yes
Application microsoft internet_explorer 3.0.2 Yes
Application microsoft internet_explorer 3.1 Yes
Application microsoft internet_explorer 3.2 Yes
Application microsoft internet_explorer 4.0 Yes
Application microsoft internet_explorer 4.0.1 Yes
Application microsoft internet_explorer 4.0.1 Yes
Application microsoft internet_explorer 4.0.1 Yes
Application microsoft internet_explorer 4.01 Yes
Application microsoft internet_explorer 4.1 Yes
Application microsoft internet_explorer 4.01 Yes
Application microsoft internet_explorer 4.5 Yes
Application microsoft internet_explorer 4.40.308 Yes
Application microsoft internet_explorer 4.40.520 Yes
Application microsoft internet_explorer 4.70.1155 Yes
Application microsoft internet_explorer 4.70.1158 Yes
Application microsoft internet_explorer 4.70.1215 Yes
Application microsoft internet_explorer 4.70.1300 Yes
Application microsoft internet_explorer 4.71.544 Yes
Application microsoft internet_explorer 4.71.1008.3 Yes
Application microsoft internet_explorer 4.71.1712.6 Yes
Application microsoft internet_explorer 4.72.2106.8 Yes
Application microsoft internet_explorer 4.72.3110.8 Yes
Application microsoft internet_explorer 4.72.3612.1713 Yes
Application microsoft internet_explorer 5 Yes
Application microsoft internet_explorer 5.0 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.00.0518.10 Yes
Application microsoft internet_explorer 5.00.0910.1309 Yes
Application microsoft internet_explorer 5.00.2014.0216 Yes
Application microsoft internet_explorer 5.00.2314.1003 Yes
Application microsoft internet_explorer 5.00.2516.1900 Yes
Application microsoft internet_explorer 5.00.2614.3500 Yes
Application microsoft internet_explorer 5.00.2919.800 Yes
Application microsoft internet_explorer 5.00.2919.3800 Yes
Application microsoft internet_explorer 5.00.2919.6307 Yes
Application microsoft internet_explorer 5.00.2920.0000 Yes
Application microsoft internet_explorer 5.00.3103.1000 Yes
Application microsoft internet_explorer 5.00.3105.0106 Yes
Application microsoft internet_explorer 5.00.3314.2101 Yes
Application microsoft internet_explorer 5.00.3315.1000 Yes
Application microsoft internet_explorer 5.00.3502.1000 Yes
Application microsoft internet_explorer 5.00.3700.1000 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.1 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.2.3 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.50.3825.1300 Yes
Application microsoft internet_explorer 5.50.4030.2400 Yes
Application microsoft internet_explorer 5.50.4134.0100 Yes
Application microsoft internet_explorer 5.50.4134.0600 Yes
Application microsoft internet_explorer 5.50.4308.2900 Yes
Application microsoft internet_explorer 5.50.4522.1800 Yes
Application microsoft internet_explorer 5.50.4807.2300 Yes
Application microsoft internet_explorer 6 Yes
Application microsoft internet_explorer 6 Yes
Application microsoft internet_explorer 6.0 Yes
Application microsoft internet_explorer 6.00.2462.0000 Yes
Application microsoft internet_explorer 6.00.2479.0006 Yes
Application microsoft internet_explorer 6.0.2600 Yes
Application microsoft internet_explorer 6.00.2600.0000 Yes
Application microsoft internet_explorer 6.0.2800 Yes
Application microsoft internet_explorer 6.0.2800.1106 Yes
Application microsoft internet_explorer 6.00.2800.1106 Yes
Application microsoft internet_explorer 6.0.2900 Yes
Application microsoft internet_explorer 6.0.2900.2180 Yes
Application microsoft internet_explorer 6.00.2900.2180 Yes
Application microsoft internet_explorer 6.00.3663.0000 Yes
Application microsoft internet_explorer 6.00.3718.0000 Yes
Application microsoft internet_explorer 6.00.3790.0000 Yes
Application microsoft internet_explorer 6.00.3790.1830 Yes
Application microsoft internet_explorer 6.00.3790.3959 Yes
Application microsoft internet_explorer 7 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0.5730 Yes
Application microsoft internet_explorer 7.0.5730.11 Yes
Application microsoft internet_explorer 7.00.5730.1100 Yes
Application microsoft internet_explorer 7.00.6000.16386 Yes
Application microsoft internet_explorer 7.00.6000.16441 Yes

References