Описание
Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecified vectors.
Ссылки
- Vendor Advisory
- PatchUS Government Resource
- PatchUS Government Resource
- Vendor Advisory
- Vendor Advisory
- PatchUS Government Resource
- PatchUS Government Resource
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microsoft:ie:5.0:sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.64171
Средний
7.5 High
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
почти 4 года назад
Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecified vectors.
EPSS
Процентиль: 98%
0.64171
Средний
7.5 High
CVSS2
Дефекты
CWE-20