CVE-2010-0806
Last modified
CVE-2010-0806 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability.". CISA has confirmed active exploitation in the wild. EPSS estimates a 82.05% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Internet Explorer | 5.01 | — |
| Microsoft | Internet Explorer | 6 | Sp1 |
| Microsoft | Internet Explorer | 8 | — |
| Microsoft | Internet Explorer | 7 | — |
References
- http://osvdb.org/62810Broken Link
- http://secunia.com/advisories/38860Vendor Advisory
- http://www.kb.cert.org/vuls/id/744549Patch, US Government Resource
- http://www.microsoft.com/technet/security/advisory/981374.mspxBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/38615Broken Link
- http://www.us-cert.gov/cas/techalerts/TA10-068A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-089A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/0567Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0744Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56772Third Party Advisory, VDB Entry
- http://osvdb.org/62810Broken Link
- http://secunia.com/advisories/38860Vendor Advisory
- http://www.kb.cert.org/vuls/id/744549Patch, US Government Resource
- http://www.microsoft.com/technet/security/advisory/981374.mspxBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/38615Broken Link
- http://www.us-cert.gov/cas/techalerts/TA10-068A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-089A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/0567Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0744Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56772Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0806US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2010-0806?
How severe is CVE-2010-0806?
How do I fix CVE-2010-0806?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-0800SQL injection vulnerability in the Ossolution Team Documents…
- CVE-2010-0801Directory traversal vulnerability in the AutartiTarot (com_a…
- CVE-2010-0802SQL injection vulnerability in index.php in (nv2) Awards 1.1…
- CVE-2010-0803SQL injection vulnerability in the jVideoDirect (com_jvideod…
- CVE-2010-0804Cross-site scripting (XSS) vulnerability in index.php in iBo…
- CVE-2010-0805The Tabular Data Control (TDC) ActiveX control in Microsoft …
- CVE-2010-0807Microsoft Internet Explorer 7 does not properly handle objec…
- CVE-2010-0808Microsoft Internet Explorer 6 and 7 on Windows XP and Vista …
- CVE-2010-0809Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2010-0810The kernel in Microsoft Windows Vista Gold, SP1, and SP2, an…
- CVE-2010-0811Multiple unspecified vulnerabilities in the Microsoft Intern…
- CVE-2010-0812Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gol…
Are you affected by CVE-2010-0806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
