9.3

CVE-2009-0075

Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftInternet Explorer Version7
   MicrosoftWindows Server 2003 Version-
   MicrosoftWindows Server 2003 Version- Updatesp1
   MicrosoftWindows Server 2003 Version- Updatesp1 Editionitanium
   MicrosoftWindows Server 2003 Version- Updatesp2
   MicrosoftWindows Server 2008
   MicrosoftWindows Server 2008 Version- Editionitanium
   MicrosoftWindows Vista Version- HwPlatformx64
   MicrosoftWindows Vista Version- Updatesp1 HwPlatformx64
   MicrosoftWindows Xp Version- Editionprofessional HwPlatformx64
   MicrosoftWindows Xp Version- Updatesp2
   MicrosoftWindows Xp Version- Updatesp2 Editionprofessional HwPlatformx64
   MicrosoftWindows Xp Version- Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 84.85% 0.993
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C