CVE-2010-0491
Internet Explorer 5.01 SP4, 6, 6 SP1 - Use-After-Free via HTML Object Property Manipulation
Title source: llmDescription
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."
References (8)
Core 8
Core References
Third Party Advisory third-party-advisory
x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=864
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8421
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/39027
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-089A.html
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-068A.html
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-018
Patch, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0744
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1023773
Scores
EPSS
0.2928
EPSS Percentile
98.0%
Details
CWE
CWE-399
Status
published
Products (6)
microsoft/internet_explorer
6 (2 CPE variants)
microsoft/internet_explorer
5.01 sp4
microsoft/windows_2000
microsoft/windows_2003_server
microsoft/windows_server_2003
microsoft/windows_xp
(3 CPE variants)
Published
Mar 31, 2010
Tracked Since
Feb 18, 2026