Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-0255
Description:Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.
Test IDs: 1.3.6.1.4.1.25623.1.0.800461  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-0255
BugTraq ID: 38055
http://www.securityfocus.com/bid/38055
BugTraq ID: 38056
http://www.securityfocus.com/bid/38056
Bugtraq: 20100203 CORE-2009-0625: Internet Explorer Dynamic OBJECT tag and URLMON sniffing vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/509345/100/0/threaded
Cert/CC Advisory: TA10-159B
http://www.us-cert.gov/cas/techalerts/TA10-159B.html
http://isc.sans.org/diary.html?n&storyid=8152
http://www.coresecurity.com/content/internet-explorer-dynamic-object-tag
Microsoft Security Bulletin: MS10-035
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-035
http://osvdb.org/62156
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7145




© 1998-2025 E-Soft Inc. All rights reserved.