Описание
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
Ссылки
- Broken LinkPermissions Required
- PatchVendor Advisory
- Press/Media Coverage
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Broken Link
- Broken Link
- Third Party AdvisoryUS Government Resource
- Broken Link
- PatchVendor Advisory
- Broken LinkExploit
- Broken LinkPermissions Required
- PatchVendor Advisory
- Press/Media Coverage
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Broken Link
- Broken Link
- Third Party AdvisoryUS Government Resource
- Broken Link
Уязвимые конфигурации
Одновременно
Одно из
Одновременно
Одно из
EPSS
8.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
Уязвимость браузера Internet Explorer, позволяющая злоумышленнику выполнить произвольный код
EPSS
8.8 High
CVSS3
9.3 Critical
CVSS2