9.3

CVE-2008-0077

Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 6 Update sp1
   Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Internet Explorer Version 6
   Microsoft ≫ Windows 2003 Server Update sp1 Edition itanium
   Microsoft ≫ Windows 2003 Server Update sp2
   Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
   Microsoft ≫ Windows 2003 Server Version - Update sp1
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Server 2003 Update sp2
   Microsoft ≫ Windows Xp Update sp2
   Microsoft ≫ Windows Xp Version - Update gold Edition x64
   Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Internet Explorer Version 7
   Microsoft ≫ Windows 2003 Server Update sp1
   Microsoft ≫ Windows 2003 Server Update sp1 Edition itanium
   Microsoft ≫ Windows 2003 Server Update sp2
   Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
   Microsoft ≫ Windows Vista
   Microsoft ≫ Windows Vista Edition x64
   Microsoft ≫ Windows Xp Update sp2
   Microsoft ≫ Windows Xp Version - Update gold Edition x64
   Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 37.19% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

http://marc.info/?l=bugtraq&m=120361015026386&w=2
Mailing List
http://www.us-cert.gov/cas/techalerts/TA08-043C.html
Third Party Advisory
US Government Resource
Broken Link
http://www.vupen.com/english/advisories/2008/0512/references
Vendor Advisory
Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010
Patch
Vendor Advisory
http://secunia.com/advisories/28903
Vendor Advisory
Broken Link
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=661
Broken Link
http://www.kb.cert.org/vuls/id/228569
Third Party Advisory
US Government Resource
http://www.securityfocus.com/archive/1/488048/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/27666
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1019380
Third Party Advisory
Broken Link
VDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-08-006.html
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5396
Broken Link