9.3
CVSSv2

CVE-2009-0553

Published: 15/04/2009 Updated: 14/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote malicious users to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet_explorer 6

microsoft internet_explorer 7

Exploits

<BODY onload=go()></BODY> <!-- MS09-014: MSIE EMBED element race condition memory corruption Code by SkyLined <berendjanwever@gmailcom> skyphercom/SkyLined/Repro/MSIE/EMBED%20memory%20corruption/repro3html skyphercom/indexphp/2009/04/19/ms09-014-embed-element-memory-corruption --> <SCRIPT> var asMim ...