← Back

CVE-2011-2382

nvd nist
Published: Jun 3, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.

Affected (97)

2 products
Ie
Internet Explorer
Configuration A
97 vulnerable
Vulnerable SoftwareAffected Versions
Version 9 beta
Microsoft
Up to 8
Version 3.0.1
Version 3.0.2
Version 3.0
Version 3.1
Version 3.2
Version 4.0.1
Version 4.0.1 sp1
Version 4.0.1 sp2
Version 4.01
Version 4.01 sp1
Version 4.0
Version 4.1
Version 4.40.308
Version 4.40.520
Version 4.5
Version 4.70.1155
Version 4.70.1158
Version 4.70.1215
Version 4.70.1300
Version 4.71.1008.3
Version 4.71.1712.6
Version 4.71.544
Version 4.72.2106.8
Version 4.72.3110.8
Version 4.72.3612.1713
Version 5.0.1
Version 5.0.1 sp1
Version 5.0.1 sp2
Version 5.0.1 sp3
Version 5.0.1 sp4
Version 5.00.0518.10
Version 5.00.0910.1309
Version 5.00.2014.0216
Version 5.00.2314.1003
Version 5.00.2516.1900
Version 5.00.2614.3500
Version 5.00.2919.3800
Version 5.00.2919.6307
Version 5.00.2919.800
Version 5.00.2920.0000
Version 5.00.3103.1000
Version 5.00.3105.0106
Version 5.00.3314.2101
Version 5.00.3315.1000
Version 5.00.3502.1000
Version 5.00.3700.1000
Version 5.01
Version 5.01 sp1
Version 5.01 sp2
Version 5.01 sp3
Version 5.01 sp4
Version 5.0
Version 5.1
Version 5.2.3
Version 5.50.3825.1300
Version 5.50.4030.2400
Version 5.50.4134.0100
Version 5.50.4134.0600
Version 5.50.4308.2900
Version 5.50.4522.1800
Version 5.50.4807.2300
Version 5.5
Version 5.5 preview
Version 5.5 sp1
Version 5.5 sp2
Version 5
Version 6.0.2600
Version 6.0.2800.1106
Version 6.0.2800
Version 6.0.2900.2180
Version 6.0.2900
Version 6.00.2462.0000
Version 6.00.2479.0006
Version 6.00.2600.0000
Version 6.00.2800.1106
Version 6.00.2900.2180
Version 6.00.3663.0000
Version 6.00.3718.0000
Version 6.00.3790.0000
Version 6.00.3790.1830
Version 6.00.3790.3959
Version 6.0
Version 6
Version 6 sp1
Version 7.0.5730.11
Version 7.0.5730 unknown
Version 7.00.5730.1100
Version 7.00.6000.16386
Version 7.00.6000.16441
Version 7.0
Version 7.0 beta1
Version 7.0 beta2
Version 7.0 beta3
Version 7.0 beta
Version 7

References (20)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.