CVE-2010-3886
medium · 4.3The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
4.3
CVSS
16.5%
EPSS (exploit prob.)
97th
EPSS percentile
2010-10-08
Published
AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_explorer | 8 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.html
- http://twitter.com/WisecWisec/statuses/17254776077
- http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100630
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11606
- http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.html
- http://twitter.com/WisecWisec/statuses/17254776077
- http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100630
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11606
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-3886