Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-07T10:31:27.906Z
Reserved: 2008-10-31T00:00:00
Link: CVE-2008-4844
No data.
Status : Deferred
Published: 2008-12-11T15:30:00.393
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4844
No data.
OpenCVE Enrichment
No data.
Weaknesses