CVE-2014-2804: Buffer Overflow
Published Jul 8, 2014
·Updated
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2798.
Affected Software
4 affected components
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Jul 8, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
Which Internet Explorer versions are affected?
Microsoft Internet Explorer versions 8 through 11 are affected.
2
Can this be exploited remotely without authentication?
Yes. The vulnerability has network attack vector and no authentication requirement; an attacker can use a crafted web site to trigger memory corruption.
3
What impact can successful exploitation have?
A successful attack can result in arbitrary code execution or a denial of service through memory corruption. The listed impacts include compromise of confidentiality, integrity, and availability.