Description
The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
References (1)
Core 1
Core References
Exploit x_refsource_misc
http://w2spconf.com/2010/papers/p26.pdf
Scores
EPSS
0.1274
EPSS Percentile
95.9%
Details
CWE
CWE-264
Status
published
Products (43)
microsoft/ie
7.0.6000.16711
microsoft/ie
8.0.7600.16385
microsoft/ie
8.0b
microsoft/internet_explorer
3.0
microsoft/internet_explorer
3.0.1
microsoft/internet_explorer
3.0.2
microsoft/internet_explorer
3.1
microsoft/internet_explorer
3.2
microsoft/internet_explorer
4.0
microsoft/internet_explorer
4.0.1 (3 CPE variants)
... and 33 more
Published
Dec 07, 2011
Tracked Since
Feb 18, 2026