CVE-2014-2796: Buffer Overflow
Published Aug 12, 2014
·Updated
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.
Affected Software
2 affected components
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Aug 12, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
Which Internet Explorer versions are affected?
Microsoft Internet Explorer 10 and 11 are affected.
2
What does an attacker need to do to exploit this issue?
An attacker needs to cause a target to process a crafted web site. The vulnerability is remotely exploitable and requires no authentication.
3
What could successful exploitation allow?
Successful exploitation could allow arbitrary code execution or cause a denial of service through memory corruption.