CVE-2010-3886

The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*

History

18 Feb 2022, 18:39

Type Values Removed Values Added
References (MISC) http://twitter.com/WisecWisec/statuses/17254776077 - (MISC) http://twitter.com/WisecWisec/statuses/17254776077 - Third Party Advisory
References (MISC) http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100630 - (MISC) http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2010/20100630 - Not Applicable
References (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11606 - (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11606 - Third Party Advisory
References (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.html - Exploit (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.html - Broken Link, Exploit

23 Jul 2021, 15:12

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:ie:8:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*

Information

Published : 2010-10-08 22:00

Updated : 2024-02-04 17:54


NVD link : CVE-2010-3886

Mitre link : CVE-2010-3886

CVE.ORG link : CVE-2010-3886


JSON object : View

Products Affected

microsoft

  • internet_explorer
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor