Back to search
CVE-2014-0322
Published: Feb 14, 2014
Modified: Oct 22, 2025
PUBLISHED
Description
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
103354
vdb-entry
x_refsource_OSVDB
32851
exploit
x_refsource_EXPLOIT-DB
http://technet.microsoft.com/security/advisory/2934088
x_refsource_CONFIRM
MS14-012
vendor-advisory
x_refsource_MS
VU#732479
third-party-advisory
x_refsource_CERT-VN
http://twitter.com/nanoc0re/statuses/434251658344673281
x_refsource_MISC
https://www.dropbox.com/s/pyxjgycmudirbqe/CVE-2014-0322.zip
x_refsource_MISC
32904
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now