CVE-2011-0346: Use After Free
Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by crossfuzz, aka "MSHTML Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0346?
CVE-2011-0346 is classified as critical due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2011-0346?
To fix CVE-2011-0346, users should update Microsoft Internet Explorer to the latest version available, including all security patches.
Which versions of Internet Explorer are affected by CVE-2011-0346?
CVE-2011-0346 affects Internet Explorer versions 6, 7, and 8.
What are the potential impacts of CVE-2011-0346?
Exploitation of CVE-2011-0346 can lead to application crashes or execution of malicious code on the user's system.
Are there any workarounds for CVE-2011-0346?
As a workaround for CVE-2011-0346, users can consider using an alternative web browser until a patch is applied.