Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Microsoft Internet Explorer DHTML Method Buffer Overflow Vulnerability

Microsoft Internet Explorer is prone to a heap-based buffer-overflow vulnerability caused by a boundary condition error that is exposed when passing data to the 'createControlRange()' DHTML method. As a result, heap-based memory can be corrupted with attacker-supplied data.

An attacker could exploit this issue to execute arbitrary code in the context of the currently logged-in user.







 

Privacy Statement
Copyright 2008, SecurityFocus