Lucene search

K
cve[email protected]CVE-2012-0012
HistoryFeb 14, 2012 - 10:55 p.m.

CVE-2012-0012

2012-02-1422:55:01
CWE-665
web.nvd.nist.gov
125
microsoft
internet explorer 9
cve-2012-0012
null byte
information disclosure
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.957 High

EPSS

Percentile

99.4%

Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka “Null Byte Information Disclosure Vulnerability.”

Affected configurations

NVD
Node
microsoftinternet_explorerMatch9
AND
microsoftwindows_7Match-
OR
microsoftwindows_7Match-sp1
OR
microsoftwindows_server_2008Match-sp2
OR
microsoftwindows_server_2008Matchr2
OR
microsoftwindows_server_2008Matchr2sp1
OR
microsoftwindows_vistaMatch-sp2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.957 High

EPSS

Percentile

99.4%