CVE Database
/

CVE-2010-3962

Back to search

CVE-2010-3962

Published: Nov 5, 2010

Modified: Oct 22, 2025

PUBLISHED

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.

VendorProductVersions

n/a

n/a

affected
n/a

References

44536
vdb-entry
x_refsource_BID
TA10-348A
third-party-advisory
x_refsource_CERT
MS10-090
vendor-advisory
x_refsource_MS
VU#899748
third-party-advisory
x_refsource_CERT-VN
42091
third-party-advisory
x_refsource_SECUNIA
ADV-2010-2880
vdb-entry
x_refsource_VUPEN
1024676
vdb-entry
x_refsource_SECTRACK
15421
exploit
x_refsource_EXPLOIT-DB
ms-ie-flag-code-execution(62962)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:12279
vdb-entry
signature
x_refsource_OVAL
15418
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now