Vulnerability Name: | CVE-2012-1526 (CCN-77343) | ||||||||
Assigned: | 2012-08-14 | ||||||||
Published: | 2012-08-14 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-1526 Source: CCN Type: SA50237 Microsoft Internet Explorer Multiple Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS12-052 Cumulative Security Update for Internet Explorer (2722913) Source: CCN Type: BID-54950 Microsoft Internet Explorer Layout Remote Memory Corruption Vulnerability Source: CERT Type: US Government Resource TA12-227A Source: MS Type: UNKNOWN MS12-052 Source: XF Type: UNKNOWN ie-layout-memory-code-execution(77343) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:15240 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |