Lucene search

K
cveMicrosoftCVE-2014-1816
HistoryJun 11, 2014 - 4:56 a.m.

CVE-2014-1816

2014-06-1104:56:18
CWE-264
microsoft
web.nvd.nist.gov
29
cve-2014-1816
msxml
information disclosure
vulnerability
internet explorer
security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.006

Percentile

78.3%

Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka “MSXML Entity URI Vulnerability.”

Affected configurations

Nvd
Node
microsoftxml_core_servicesMatch3.0
OR
microsoftxml_core_servicesMatch6.0
VendorProductVersionCPE
microsoftxml_core_services3.0cpe:2.3:a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*
microsoftxml_core_services6.0cpe:2.3:a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.006

Percentile

78.3%