CVE-2016-7282
MEDIUMMicrosoft Edge - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
References (4)
Scores
CVSS v3
6.1
EPSS
0.0520
EPSS Percentile
89.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (5)
microsoft/edge
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
n/a/n/a
Timeline
Published
Dec 20, 2016
Tracked Since
Feb 18, 2026