Browser

Information Disclosure

Microsoft Internet Explorer CDOMStringDataList::InitFromString Out-Of-Bounds Indexing Information Disclosure Vulnerability

Microsoft Internet Explorer CDOMStringDataList::InitFromString Out-Of-Bounds Indexing Information Disclosure Vulnerability This vulnerability allows remote attackers to disclose sensitive information…

4.3
/ 10
Medium
CVSS v2.0
ADVISORY ID
PS3
PUBLISHED
2022-10-02
CVE IDs
CVE-2015-6086
VENDORS
Microsoft
PUBLIC EXPLOIT
None indexed
CWE
CWE-200
PRODUCT
Internet Explorer
CVSS VECTOR
AV:N/AC:M/Au:N/C:P/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Microsoft Internet Explorer CDOMStringDataList::InitFromString Out-Of-Bounds Indexing Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within CDOMStringDataList::InitFromString. By manipulating a document’s elements an attacker can read outside the bounds of an allocated chunk. An attacker can leverage this vulnerability to leak arbitrary memory.

Vulnerability details

Vulnerability details

CVE-2015-6086
CWE-200
Medium | 4.3

Microsoft Internet Explorer CDOMStringDataList::InitFromString Out-Of-Bounds Indexing Information Disclosure Vulnerability This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Microsoft Internet Explorer.

Auth:
None (remote)
Impact:
Partial data disclosure
DISCLOSURE

Disclosure timeline

2015-09-08 Vulnerability reported to vendor

2015-11-10 Coordinated public release of advisory

Credits

Ashfaq Ansari – Project Srishti – Payatu Technologies