CVE-2014-0284: Buffer Overflow
Published Feb 12, 2014
·Updated
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
2 affected components
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Event History
Feb 12, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:50 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which Internet Explorer versions are affected?
The affected versions identified are Microsoft Internet Explorer 9 and 10.
2
What does an attacker need to do to exploit this issue?
An attacker can trigger the memory corruption by getting a victim to access a crafted web site. The supplied vector is network-based and requires no authentication.
3
What could successful exploitation allow?
Successful exploitation may allow remote arbitrary code execution or cause a denial of service through memory corruption.