CVE-2014-2768: Buffer Overflow
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2773.
Affected Software
Event History
Frequently Asked Questions
Which Internet Explorer installations are affected?
Microsoft Internet Explorer versions 6 through 8 are affected. The provided data does not identify any affected operating system versions or configurations.
What must an attacker do to exploit this issue?
An attacker needs to get a user to access a crafted web site. The vulnerability is remotely exploitable and requires no authentication.
What could successful exploitation allow?
Successful exploitation can result in arbitrary code execution or a denial of service through memory corruption. The supplied severity vector indicates impacts to confidentiality, integrity, and availability.