| |||||||||||||
| CVE ID: | CVE-2008-4261 |
| Description: | Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability." |
| Test IDs: | None available |
| Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-4261 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=761 Microsoft Security Bulletin: MS08-073 http://www.microsoft.com/technet/security/Bulletin/MS08-073.mspx Cert/CC Advisory: TA08-344A http://www.us-cert.gov/cas/techalerts/TA08-344A.html http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5829 http://www.vupen.com/english/advisories/2008/3385 http://www.securitytracker.com/id?1021371 |
|