Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mj6r-fxqr-4c2f

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.

EPSS

Процентиль: 99%
0.86119
Высокий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 13 лет назад

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.

EPSS

Процентиль: 99%
0.86119
Высокий

Дефекты

CWE-94