9.3
CVSSv2

CVE-2011-1255

Published: 16/06/2011 Updated: 28/02/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote malicious users to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Time Element Memory Corruption Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet_explorer 6

microsoft internet_explorer 7

microsoft internet_explorer 8

Exploits

###################################################################################### # Vuln Title: Internet Explorer Remote Code Execution Exploit (DEP and ASLR Bypass) # # Author: FaryadR (aka Ciph3r) # tested on : win 7 and IE 8 (DEP and ASLR) # Twitter : twittercom/faryadR # Mail : Ciph3rsecure@gmailcom # Website : 0c0c0c0 ...

Recent Articles

Patch Tuesday June 2011
Securelist • Kurt Baumgartner • 14 Jun 2011

This month’s patch Tuesday is a sizable one by any standards, following the quiet Tuesday that my colleague Roel Schouwenberg described last month. Microsoft is patching a total of 34 vulnerabilities in 16 bulletins, MS11-038 through MS11-051. At least eight different Microsoft product lines are updated, and Adobe is coordinating release of Reader, Acrobat, Shockwave and Flash updates as well today. So we are looking at patching the following programs: Microsoft Windows, Microsoft Office, Inte...