Description
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-07T10:31:27.906Z
Reserved: 2008-10-31T00:00:00.000Z
Link: CVE-2008-4844
No data.
Status : Modified
Published: 2008-12-11T15:30:00.393
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-4844
No data.
OpenCVE Enrichment
No data.
Weaknesses