CVE-2016-3351

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*

History

28 Jan 2025, 18:19

Type Values Removed Values Added
References (BID) http://www.securityfocus.com/bid/92788 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92788 - Broken Link, Third Party Advisory, VDB Entry
References (SECTRACK) http://www.securitytracker.com/id/1036789 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1036789 - Broken Link, Third Party Advisory, VDB Entry
References (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - Patch, Vendor Advisory () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - Patch, Vendor Advisory
References (MISC) https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - Exploit () https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - Exploit
References (SECTRACK) http://www.securitytracker.com/id/1036788 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1036788 - Broken Link, Third Party Advisory, VDB Entry
References (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - Patch, Vendor Advisory () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - Patch, Vendor Advisory

02 Jul 2024, 12:23

Type Values Removed Values Added
References (MISC) https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - (MISC) https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ - Exploit
References (BID) http://www.securityfocus.com/bid/92788 - (BID) http://www.securityfocus.com/bid/92788 - Broken Link, Third Party Advisory, VDB Entry
References (SECTRACK) http://www.securitytracker.com/id/1036788 - (SECTRACK) http://www.securitytracker.com/id/1036788 - Broken Link, Third Party Advisory, VDB Entry
References (SECTRACK) http://www.securitytracker.com/id/1036789 - (SECTRACK) http://www.securitytracker.com/id/1036789 - Broken Link, Third Party Advisory, VDB Entry
References (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 - Patch, Vendor Advisory
References (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 - Patch, Vendor Advisory
CVSS v2 : 2.6
v3 : 3.1
v2 : 2.6
v3 : 6.5
CPE cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
First Time Microsoft windows 7
Microsoft windows Vista
Microsoft windows 8.1
Microsoft windows 10 1507
Microsoft windows 10 1511
Microsoft windows Server 2012
Microsoft windows Rt 8.1
Microsoft windows Server 2008
Microsoft windows 10 1607
CWE CWE-200 NVD-CWE-noinfo

Information

Published : 2016-09-14 10:59

Updated : 2025-04-04 20:43


NVD link : CVE-2016-3351

Mitre link : CVE-2016-3351


JSON object : View

Products Affected

microsoft

  • windows_7
  • windows_8.1
  • windows_10_1607
  • windows_vista
  • internet_explorer
  • edge
  • windows_server_2012
  • windows_10_1511
  • windows_rt_8.1
  • windows_10_1507
  • windows_server_2008