Anfälligkeitssuche        Suche in 191973 CVE Beschreibungen
und 86218 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

CVE Kennung:CVE-2010-3886
Beschreibung:The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
Test Kennungen: 1.3.6.1.4.1.25623.1.0.801606  
Querverweise: Common Vulnerability Exposure (CVE) ID: CVE-2010-3886
Bugtraq: 20100629 [0day] Microsoft mshtml.dll CTimeoutEventList::InsertIntoTimeoutList memory leak (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.html
http://twitter.com/WisecWisec/statuses/17254776077
http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100630
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11606




© 1998-2020 E-Soft Inc. Alle Rechte vorbehalten.