CVE-2009-2655
published 2009-08-03CVE-2009-2655: mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
22.56%
97.4th percentile
mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://www.exploit-db.com/exploits/9253http://www.securityfocus.com/bid/35799https://exchange.xforce.ibmcloud.com/vulnerabilities/52249https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12700http://www.exploit-db.com/exploits/9253http://www.securityfocus.com/bid/35799https://exchange.xforce.ibmcloud.com/vulnerabilities/52249https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12700
2009-08-03
Published