Описание
Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."
Ссылки
- Third Party AdvisoryUS Government Resource
- PatchVendor Advisory
- Tool Signature
- Third Party AdvisoryUS Government Resource
- PatchVendor Advisory
- Tool Signature
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
Одно из
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.16456
Средний
4.3 Medium
CVSS2
Дефекты
CWE-665
Связанные уязвимости
github
почти 4 года назад
Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."
EPSS
Процентиль: 95%
0.16456
Средний
4.3 Medium
CVSS2
Дефекты
CWE-665