Microsoft Internet Explorer Multiple Vulnerabilities
Last Update Date:
13 Jun 2012 15:18
Release Date:
13 Jun 2012
4666
Views
RISK: High Risk
TYPE: Clients - Browsers
- Center Element Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - HTML Sanitization Vulnerability
An information disclosure vulnerability exists in the way that Internet Explorer handles content using specific strings when sanitizing HTML. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow information disclosure if a user viewed the Web page. An attacker who successfully exploited this vulnerability could inflict cross-site scripting on the user, allowing the attacker to execute script in the user's security context against a site that is using the toStaticHTML method. - EUC-JP Character Encoding Vulnerability
An information disclosure vulnerability exists in Internet Explorer that could allow script to perform Cross-Site Scripting attacks. An attacker could exploit the vulnerability by inserting specially crafted strings in to a website, resulting in information disclosure when a user viewed the website. - Null Byte Information Disclosure Vulnerability
An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access and read Internet Explorer's process memory. An attacker could exploit the vulnerability by constructing a specially crafted webpage that could allow information disclosure if a user viewed the webpage. An attacker who successfully exploited this vulnerability could view content from Internet Explorer's process memory. - Developer Toolbar Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - Same ID Property Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - Col Element Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that does not exist. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - Title Element Change Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - OnBeforeDeactivate Event Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - insertAdjacentText Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an undefined memory location. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - insertRow Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - OnRowsInserted Event Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - Scrolling Events Information Disclosure Vulnerability
An information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to information in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted webpage that could allow information disclosure if a user viewed the webpage. An attacker who successfully exploited this vulnerability could view content from another domain or Internet Explorer zone.
Impact
- Remote Code Execution
System / Technologies affected
- Internet Explorer 6
- Internet Explorer 7
- Internet Explorer 8
- Internet Explorer 9
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/ms12-037
Vulnerability Identifier
- CVE-2012-1523
- CVE-2012-1858
- CVE-2012-1872
- CVE-2012-1873
- CVE-2012-1874
- CVE-2012-1875
- CVE-2012-1876
- CVE-2012-1877
- CVE-2012-1878
- CVE-2012-1879
- CVE-2012-1880
- CVE-2012-1881
- CVE-2012-1882
Source
Related Link
Share with