← All CVEs

CVE-2010-0491

high · 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."

9.3
CVSS
29.3%
EPSS (exploit prob.)
98th
EPSS percentile
2010-03-31
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
microsoftinternet_explorer6
microsoftwindows_2003_serverall versions
microsoftwindows_server_2003all versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftinternet_explorer5.01
microsoftinternet_explorer6
microsoftwindows_2000all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-0491