Back to search
CVE-2011-0346
Published: Jan 7, 2011
Modified: Oct 21, 2024
PUBLISHED
Description
Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka "MSHTML Memory Corruption Vulnerability."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2011-0026
vdb-entry
x_refsource_VUPEN
TA11-102A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:11882
vdb-entry
signature
x_refsource_OVAL
ms-ie-releaseinterface-code-execution(64482)
vdb-entry
x_refsource_XF
45639
vdb-entry
x_refsource_BID
MS11-018
vendor-advisory
x_refsource_MS
20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more
mailing-list
x_refsource_FULLDISC
20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more
mailing-list
x_refsource_BUGTRAQ
http://lcamtuf.coredump.cx/cross_fuzz/known_vuln.txt
x_refsource_MISC
1024940
vdb-entry
x_refsource_SECTRACK
http://lcamtuf.coredump.cx/cross_fuzz/msie_crash.txt
x_refsource_MISC
VU#427980
third-party-advisory
x_refsource_CERT-VN
http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now