2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2008-1085" ,
"sourceIdentifier" : "secure@microsoft.com" ,
"published" : "2008-04-08T23:05:00.000" ,
2024-11-22 07:15:30 +00:00
"lastModified" : "2024-11-21T00:43:38.697" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de uso despu\u00e9s de la liberaci\u00f3n en Microsoft Internet Explorer 5.01 SP4, 6 hasta SP1, y 7, permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de una cadena de datos manipulada que provoca una corrupci\u00f3n de memoria, tal como se ha demostrado utilizando un MIME-type no v\u00e1lido que no conten\u00eda un manejador registrado."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C" ,
2024-11-22 07:15:30 +00:00
"baseScore" : 9.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
2024-11-22 07:15:30 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-94"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:*" ,
"matchCriteriaId" : "B054A26A-7414-41B2-A46D-49E798D7A346"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "B80088A3-2AA4-44A2-98DF-359E15F8E18B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:*" ,
"matchCriteriaId" : "181D0FA2-79E1-4422-9810-D7A557805872"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "81C4C1ED-AC7D-4970-8B34-62D304A83FE9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:7:*:windows_server_2003:*:*:*:*:*" ,
"matchCriteriaId" : "5B5F31E2-2060-45BC-9724-A447544905E0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:7:windows_server_2003_sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "574EE6CB-7AF4-4DE2-B668-36BBCB19FCC1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:7:windows_xp_sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "BE2858A5-C9BF-40D8-B3D2-056562BF1C87"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2:*:*:*:*:*" ,
"matchCriteriaId" : "75234062-241B-421A-B7BC-610A5B0D8EF9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2_itanium:*:*:*:*:*" ,
"matchCriteriaId" : "82D6ABD4-C607-44E8-8D84-25406AE0F3C8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition:*:*:*:*:*" ,
"matchCriteriaId" : "379FE901-58AC-4F47-9B3B-9A40D723CC88"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*" ,
"matchCriteriaId" : "EC18DBBB-9C9E-4532-B390-92C35E52943A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition:*:*:*:*:*" ,
"matchCriteriaId" : "49C8060E-CFB9-4EEA-B5B9-B7607B046AE8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*" ,
"matchCriteriaId" : "FB17CABD-21BE-454F-9602-19DB444A574C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2:*:*:*:*:*" ,
"matchCriteriaId" : "3994AE83-EC42-4893-AF51-BC98F35A53CE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2_itanium:*:*:*:*:*" ,
"matchCriteriaId" : "33F4B074-7BA5-4A36-A866-945D771D2EA5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition:*:*:*:*:*" ,
"matchCriteriaId" : "491333D2-FDB1-4FC8-B54C-19E06B57FC33"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*" ,
"matchCriteriaId" : "E8453618-EDD7-41F4-840E-AA323A873B2F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_itanium_edition:*:*:*:*:*" ,
"matchCriteriaId" : "35B0471D-79F8-4DB8-B777-57054CE11B9C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_x32_edition:*:*:*:*:*" ,
"matchCriteriaId" : "DE97ECE1-417A-4E5D-A4A6-730C10694397"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_x64_edition:*:*:*:*:*" ,
"matchCriteriaId" : "DCD51C3D-0A76-4552-A292-448C65859ED6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista:*:*:*:*:*" ,
"matchCriteriaId" : "E5E8CC5B-B8E9-4B54-AE32-4632E77F0320"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista_x64:*:*:*:*:*" ,
"matchCriteriaId" : "EA7D9655-718E-42D6-9752-64BA3AAC5546"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition:*:*:*:*:*" ,
"matchCriteriaId" : "8E5B894F-6E15-46DA-93B4-EAB9468D37A4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*" ,
"matchCriteriaId" : "CCE0AF0B-DF2A-4F3F-8F5C-0E4056A34229"
}
]
}
]
}
] ,
"references" : [
2024-11-22 07:15:30 +00:00
{
"url" : "http://marc.info/?l=bugtraq&m=120845064910729&w=2" ,
"source" : "secure@microsoft.com"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://marc.info/?l=bugtraq&m=120845064910729&w=2" ,
"source" : "secure@microsoft.com"
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/27707" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/secunia_research/2007-100/advisory/" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www.securityfocus.com/archive/1/490840/100/0/threaded" ,
"source" : "secure@microsoft.com"
} ,
{
"url" : "http://www.securityfocus.com/bid/28552" ,
"source" : "secure@microsoft.com"
} ,
{
"url" : "http://www.securitytracker.com/id?1019801" ,
"source" : "secure@microsoft.com"
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA08-099A.html" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.vupen.com/english/advisories/2008/1148/references" ,
"source" : "secure@microsoft.com"
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-024" ,
"source" : "secure@microsoft.com"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5563" ,
"source" : "secure@microsoft.com"
2024-11-22 07:15:30 +00:00
} ,
{
"url" : "http://marc.info/?l=bugtraq&m=120845064910729&w=2" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://marc.info/?l=bugtraq&m=120845064910729&w=2" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://secunia.com/advisories/27707" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/secunia_research/2007-100/advisory/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/archive/1/490840/100/0/threaded" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/28552" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securitytracker.com/id?1019801" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA08-099A.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.vupen.com/english/advisories/2008/1148/references" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-024" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5563" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}