CVE-2010-3962

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an invalid flag reference issue or Uninitialized Memory Corruption Vulnerability, as exploited in the wild in November 2010.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
87.03

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2416400) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2416400) x86 based systems for SP2Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2416400) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2416400) x86 based systems for SP2Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2416400) for SP2Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2416400) for SP2Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2416400)Windows
Cumulative Security Update for Internet Explorer for Windows XP (KB2416400)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2416400)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-9474Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2416400)
PATCH-9478Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2416400)
PATCH-9480Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2416400)
PATCH-9481Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2416400)
PATCH-9482Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2416400)
PATCH-9484Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2416400)
PATCH-9486Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2416400)
PATCH-9487Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2416400)
PATCH-9488Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2416400)
PATCH-9489Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2416400)
PATCH-9490Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2416400)
PATCH-9491Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2416400)
PATCH-9492Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2416400)
PATCH-9493Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2416400)
PATCH-9494Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2416400)
PATCH-9495Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2416400)
PATCH-9496Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2416400)
PATCH-9497Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2416400)
PATCH-9498Cumulative Security Update for Internet Explorer for Windows XP (KB2416400)
PATCH-9499Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2416400)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234