CVE-2010-3886
Summary
| CVE | CVE-2010-3886 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-10-08 22:00:36 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | 8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| Security Webinars, Podcasts, Success Stories, White Papers, and Datasheets | eEye Digital Security | af854a3a-2127-422b-91ae-364da2661108 | www.eeye.com | Not Applicable |
| archives.neohapsis.com/archives/bugtraq/2010-06/0259.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Broken Link, Exploit |
| Stefano Di Paola on Twitter: "setTimeout(alert,0 ) mem leak on FF ?" | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.