Vulnerabilities > CVE-2011-0347 - Unspecified vulnerability in Microsoft Internet Explorer
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 1 |
Oval
accepted | 2013-04-15T04:00:08.375-04:00 | ||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||
contributors |
| ||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||
description | Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz. | ||||||||||||||||||||
family | windows | ||||||||||||||||||||
id | oval:org.mitre.oval:def:12514 | ||||||||||||||||||||
status | accepted | ||||||||||||||||||||
submitted | 2011-03-18T13:10:08 | ||||||||||||||||||||
title | Vulnerability in Microsoft Internet Explorer Could Allow GUI Corruption | ||||||||||||||||||||
version | 29 |
References
- http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt
- http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html
- http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg
- http://www.microsoft.com/technet/security/advisory/2490606.mspx
- http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html
- http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64571
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12514
- http://www.securityfocus.com/archive/1/515506/100/0/threaded