CVE-2010-0491

Internet Explorer 5.01 SP4, 6, 6 SP1 - Use-After-Free via HTML Object Property Manipulation

Title source: llm
STIX 2.1

Description

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=864
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8421
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39027
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-089A.html
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-068A.html
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0744
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023773

Scores

EPSS 0.2928
EPSS Percentile 98.0%

Details

CWE
CWE-399
Status published
Products (6)
microsoft/internet_explorer 6 (2 CPE variants)
microsoft/internet_explorer 5.01 sp4
microsoft/windows_2000
microsoft/windows_2003_server
microsoft/windows_server_2003
microsoft/windows_xp (3 CPE variants)
Published Mar 31, 2010
Tracked Since Feb 18, 2026