[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-0031Date: (C)2011-02-08   (M)2023-12-22


The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1025044
SECUNIA-43249
BID-46139
OSVDB-70827
ADV-2011-0322
MS11-009
ms-win-jscript-info-disclosure(64919)
oval:org.mitre.oval:def:12313

CPE    3
cpe:/o:microsoft:windows_server_2008:r2::x64
cpe:/o:microsoft:windows_7:-
cpe:/o:microsoft:windows_server_2008:r2::itanium
CWE    1
CWE-200
OVAL    2
oval:org.secpod.oval:def:1034
oval:org.secpod.oval:def:88

© SecPod Technologies