Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jhw-qp9v-79q5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.

The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.

EPSS

Процентиль: 94%
0.14351
Средний

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 15 лет назад

The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.

EPSS

Процентиль: 94%
0.14351
Средний

Дефекты

CWE-200