PT-2009-4938 · Microsoft · Internet Explorer

Thierry Zoller

·

Published

2009-07-20

·

Updated

2018-10-10

·

CVE-2009-2536

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5 through 8
Description The issue allows remote attackers to cause a denial of service, resulting in memory consumption and application crash, by providing a large integer value for the length property of a Select object.
Recommendations For Microsoft Internet Explorer versions 5 through 8, as a temporary workaround, consider restricting the use of the Select object until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2536

Affected Products

Internet Explorer