CVE-2010-3886
Microsoft - 'MSHTML.dll' CTIMEOUTEVENTLIST::INSERTINTOTIMEOUTLIST Memory Leak
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
La función CTimeoutEventList::InsertIntoTimeoutList en el fichero mshtml.dll de Microsoft utiliza un valor de puntero para producir de valores de identificación a partir de un temporizador para los métodos setTimeout y setInterval en VBScript y JScript, lo que permite a atacantes remotos obtener información sensible acerca de las direcciones de la memoria 'heap' usada por una aplicación, como lo demuestra la aplicación Internet Explorer 8.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-07-09 First Exploit
- 2010-10-08 CVE Reserved
- 2010-10-08 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://twitter.com/WisecWisec/statuses/17254776077 | Third Party Advisory | |
http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100630 | Not Applicable | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11606 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/14295 | 2010-07-09 | |
http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.html | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Internet Explorer Search vendor "Microsoft" for product "Internet Explorer" | 8 Search vendor "Microsoft" for product "Internet Explorer" and version "8" | - |
Affected
|