CVE detail
CVE-2008-2949 — CVE-2008-2949
Published 2008-06-30 · Modified 2026-06-16 · Vendor microsoft · Product internet_explorer · Source nvd
UNKNOWN
severity
CVSS-derived band
0.2049
EPSS probability
exploitation probability, 30d
97.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References