Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2010-0255
StatusCandidate
DescriptionMicrosoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.
SeverityMedium
CVSS score4,3
CVSS vector(AV:N/AC:M/Au:N/C:P/I:N/A:N)
PhaseAssigned (21.08.2010)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0255
ReferencesBID : 38055
 BID : 38056
 BUGTRAQ : 20100203 CORE-2009-0625: Internet Explorer Dynamic OBJECT tag and URLMON sniffing vulnerabilities
 CERT : TA10-159B
 CONFIRM : http://blogs.technet.com/msrc/archive/2010/02/03/s...
 CONFIRM : http://support.avaya.com/css/P8/documents/100089747
 CONFIRM : http://www.microsoft.com/technet/security/advisory...
 MISC : http://isc.sans.org/diary.html?n&storyid=8152
 MISC : http://www.coresecurity.com/content/internet-explo...
 MS : MS10-035
 OSVDB : 62156
 OVAL : oval:org.mitre.oval:def:7145
SecurityVulns:Microsoft Internet Explorer information leak
 Microsoft Internet Explorer multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server