Vulnerability Name: | CCN-105037 | ||||||
Published: | 2015-07-20 | ||||||
Updated: | 2015-07-20 | ||||||
Summary: | Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system, caused by CTableLayout::AddRow function accessing out-of-bounds memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to execute arbitrary code on the system. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L) 4.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:W/RC:R)
| ||||||
CVSS v2 Severity: | 4.3 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: SECTRACK ID: 1033038 Microsoft Internet Explorer Mobile Flaw Array Element Out-of-Bounds Memory Access Flaw Lets Remote Users Execute Arbitrary Code Source: XF Type: UNKNOWN ms-ie-ctablelayout-code-exec(105037) Source: CCN Type: ZDI-15-359 (0Day) (Mobile Pwn2Own) Microsoft Internet Explorer CTableLayout::AddRow Out-Of-Bounds Memory Access Vulnerability | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |