CVE-2014-0269: Buffer Overflow
Published Feb 12, 2014
·Updated
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
5 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=7
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Event History
Feb 12, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:50 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which environments are exposed?
Systems running Microsoft Internet Explorer versions 6 through 10 are affected. The issue can be reached remotely through a crafted website.
2
What does an attacker need to exploit this issue?
An attacker does not need authentication. Exploitation requires convincing or otherwise causing a user of an affected Internet Explorer version to access a crafted website.
3
What could happen if exploitation succeeds?
Successful exploitation can result in arbitrary code execution or a denial of service caused by memory corruption. The vulnerability is classified as a buffer overflow.