CVE-2015-6086 is an information disclosure vulnerability affecting Microsoft Internet Explorer versions 9 through 11. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted website, leading to the disclosure of sensitive information from process memory. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and a partial impact on confidentiality, with no impact on integrity or availability. While not listed in CISA's KEV catalog, an ExploitDB entry exists for an out-of-bounds read related to this vulnerability, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.