CVE-2014-0278: Buffer Overflow
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0277 and CVE-2014-0279.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The affected software identified is Microsoft Internet Explorer 8. The provided data does not identify affected operating systems, editions, or fixed versions.
What must an attacker do to exploit this issue?
An attacker can exploit the issue remotely by serving a crafted web site. No authentication is required according to the supplied vector, but the data does not specify how a victim is directed to the site.
What impact could successful exploitation have?
Successful exploitation can allow arbitrary code execution or cause a denial of service through memory corruption. The supplied severity vector indicates potential impact to confidentiality, integrity, and availability.