CVE-2014-0280: Buffer Overflow
Published Feb 12, 2014
·Updated
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
3 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=7
Microsoft Internet Explorer=8
Event History
Feb 12, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:50 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which systems are exposed to this vulnerability?
Systems running Microsoft Internet Explorer versions 6 through 8 are affected. The issue can be triggered remotely through a crafted website.
2
What does an attacker need to exploit the issue?
An attacker needs to persuade or otherwise cause a user to access a crafted website. No authentication is required, and successful exploitation can result in arbitrary code execution or a denial of service through memory corruption.