CVE-2014-8967

Microsoft Internet Explorer - Use After Free

Title source: llm
STIX 2.1

Description

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted HTML document in conjunction with a Cascading Style Sheets (CSS) token sequence specifying the run-in value for the display property, leading to improper CElement reference counting.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71483
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-14-403/

Scores

EPSS 0.1240
EPSS Percentile 95.8%

Details

Status published
Products (1)
microsoft/internet_explorer
Published Dec 15, 2014
Tracked Since Feb 18, 2026