CVE-2010-3886

The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-10-08 22:00

Updated : 2024-02-28 11:41


NVD link : CVE-2010-3886

Mitre link : CVE-2010-3886

CVE.ORG link : CVE-2010-3886


JSON object : View

Products Affected

microsoft

  • internet_explorer
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor