PT-2016-1156 · Microsoft · Edge+1

Publicado

2016-02-09

·

Atualizado

2018-10-12

·

CVE-2016-0077

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 9 through 11 Microsoft Edge (affected versions not specified)
Description A spoofing issue exists due to the improper parsing of HTTP responses by Microsoft browsers. This allows remote attackers to spoof web sites via a crafted URL. An attacker who successfully exploits this issue could trick a user by redirecting them to a specially crafted website, which could spoof content or be used to chain an attack with other vulnerabilities in web services. To exploit the issue, the user must click a specially crafted URL.
Recommendations For Microsoft Internet Explorer versions 9 through 11, consider disabling the browser until a patch is available. For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00417
CVE-2016-0077

Produtos afetados

Edge
Internet Explorer