vendor:
Internet Explorer
by:
Hong10 & AmesianX
3,3
CVSS
LOW
MS Internet Explorer findText Unicode Parsing error
N/A
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 7
Affected Version To: Internet Explorer 8
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2009
IE findText crash
The following bug was tested on the latest version of Internet Explorer 7/8. When a user clicks on the 'exploit' button, a text field is created with an ID of 'powerhacker' and a value of 'AAAA'. A text range is then created from the text field and a findText method is called with a Unicode string that is longer than the allocated stack memory. This causes a crash in Internet Explorer 7/8.
Mitigation:
N/A