Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1085

Опубликовано: 08 апр. 2008
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:7:*:windows_server_2003:*:*:*:*:*
cpe:2.3:a:microsoft:ie:7:windows_server_2003_sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:7:windows_xp_sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2_itanium:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2_itanium:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_itanium_edition:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_x32_edition:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_x64_edition:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista_x64:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*

EPSS

Процентиль: 97%
0.4438
Средний

9.3 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler.

EPSS

Процентиль: 97%
0.4438
Средний

9.3 Critical

CVSS2

Дефекты

CWE-94