CVE-2014-0276: Buffer Overflow
Published Feb 12, 2014
·Updated
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
2 affected components
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Event History
Feb 12, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:50 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this vulnerability?
An attacker needs to induce a user to visit a crafted website. The vulnerability is remotely exploitable and does not require authentication.
2
Which Internet Explorer versions are identified as affected?
The affected versions identified are Microsoft Internet Explorer 8 and Internet Explorer 9.
3
What impact can successful exploitation have?
Successful exploitation can allow arbitrary code execution or cause a denial of service through memory corruption. The listed impact includes compromise of confidentiality, integrity, and availability.