CVE-2010-3971
EXPLOITEDMicrosoft Internet Explorer - Resource Management Error
Title source: ruleDescription
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16533
exploitdb
WORKING POC
VERIFIED
by Nephi Johnson · rubyremotewindows
https://www.exploit-db.com/exploits/15746
metasploit
WORKING POC
GOOD
by passerby, d0c_s4vage, jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms11_003_ie_css_import.rb
References (16)
Scores
EPSS
0.8560
EPSS Percentile
99.4%
Details
VulnCheck KEV
2011-03-08
CWE
CWE-399
Status
published
Products (2)
microsoft/internet_explorer
7
microsoft/internet_explorer
8
Published
Dec 22, 2010
Tracked Since
Feb 18, 2026