CVE-2010-3886
Last modified
CVE-2010-3886 is a vulnerability of currently unknown severity. The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.. EPSS estimates a 16.80% chance of exploitation in the next 30 days.
Description
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | 8 |
References
- http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.htmlBroken Link, Exploit
- http://twitter.com/WisecWisec/statuses/17254776077Third Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2010-06/0259.htmlBroken Link, Exploit
- http://twitter.com/WisecWisec/statuses/17254776077Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3886?
How severe is CVE-2010-3886?
How do I fix CVE-2010-3886?
Are you affected by CVE-2010-3886?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
