First published: Fri Jul 10 2009(Updated: )
Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =8.0b | |
Internet Explorer | =7 | |
Internet Explorer | =7.0.5730-unknown | |
Internet Explorer | =7.0-beta | |
Internet Explorer | =7.0 | |
Internet Explorer | =7.0.5730.11 | |
Internet Explorer | =7.0-beta1 | |
Internet Explorer | =7.0-beta2 | |
Internet Explorer | =7.0-beta3 | |
Internet Explorer | =7.00.5730.1100 | |
Internet Explorer | =7.00.6000.16386 | |
Internet Explorer | =7.00.6000.16441 | |
Internet Explorer | =8.0.6001-beta | |
Internet Explorer | =8.0.6001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2433 has a moderate severity level due to the potential for denial of service and application crashes.
To fix CVE-2009-2433, ensure that you are using the latest version of Internet Explorer and apply any available security patches.
CVE-2009-2433 affects Internet Explorer versions 7 and 8, including various beta releases.
CVE-2009-2433 is classified as a stack-based buffer overflow vulnerability.
Yes, CVE-2009-2433 can be exploited remotely through a specially crafted URL.