Lucene search

K
cve[email protected]CVE-2010-3971
HistoryDec 22, 2010 - 9:00 p.m.

CVE-2010-3971

2010-12-2221:00:17
CWE-399
web.nvd.nist.gov
47
cve-2010-3971
use-after-free
remote code execution
denial of service
css parser
internet explorer
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.971 High

EPSS

Percentile

99.8%

Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka “CSS Memory Corruption Vulnerability.”

Affected configurations

NVD
Node
microsoftinternet_explorerMatch7
OR
microsoftinternet_explorerMatch8

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.971 High

EPSS

Percentile

99.8%