Section: .. / 0806-advisories /
| /// File Name: |
ZDI-08-039.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of various Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the substringData() method when called on a DOM object that has been manipulated in a special way. The attack results in an exploitable heap buffer allowing for code execution under the context of the current user.
| | Author: | Sebastian Apelt, Peter Vreugdenhil | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3286 | | Related CVE(s): | CVE-2008-1442 | | Last Modified: | Jun 10 22:48:20 2008 |
| MD5 Checksum: | 9aedb0de93f37d59642ba58f762c6f66 |
|
| /// File Name: |
ZDI-08-040.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists in the parsing of SAMI files. When handling the properties of a "Class Name" variable a lack of bounds checking can result in a stack overflow. Successful exploitation can lead to remote code execution under the credentials of the logged in user.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3179 | | Related CVE(s): | CVE-2008-1444 | | Last Modified: | Jun 10 22:49:24 2008 |
| MD5 Checksum: | 095e694f129da80579773b65d8cd340f |
|
|
|
|
|