{"api_version":"1","generated_at":"2026-07-23T03:09:21+00:00","cve":"CVE-2011-0347","urls":{"html":"https://cve.report/CVE-2011-0347","api":"https://cve.report/api/cve/CVE-2011-0347.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0347","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0347"},"summary":{"title":"CVE-2011-0347","description":"Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-01-07 23:00:20","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/515506/100/0/threaded","name":"http://www.securityfocus.com/archive/1/515506/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.microsoft.com/technet/security/advisory/2490606.mspx","name":"http://www.microsoft.com/technet/security/advisory/2490606.mspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft Security Advisory (2490606): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx","name":"http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Assessing the risk of public issues currently being tracked by the MSRC - Security Research & Defense - Site Home - TechNet Blogs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html","name":"http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"lcamtuf's blog: Announcing cross_fuzz, a potential 0-day in circulation, and more","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg","name":"http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"403"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64571","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt","name":"http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"403"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12514","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12514","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0347","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0347","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"347","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"347","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:51:08.493Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx"},{"name":"ms-ie-gui-weak-security(64571)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64571"},{"name":"20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html"},{"name":"20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/515506/100/0/threaded"},{"name":"oval:org.mitre.oval:def:12514","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12514"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.microsoft.com/technet/security/advisory/2490606.mspx"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-01-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html"},{"tags":["x_refsource_MISC"],"url":"http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx"},{"name":"ms-ie-gui-weak-security(64571)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64571"},{"name":"20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html"},{"name":"20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/515506/100/0/threaded"},{"name":"oval:org.mitre.oval:def:12514","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12514"},{"tags":["x_refsource_MISC"],"url":"http://www.microsoft.com/technet/security/advisory/2490606.mspx"},{"tags":["x_refsource_MISC"],"url":"http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt"},{"tags":["x_refsource_MISC"],"url":"http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-0347","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html","refsource":"MISC","url":"http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html"},{"name":"http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx","refsource":"MISC","url":"http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx"},{"name":"ms-ie-gui-weak-security(64571)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64571"},{"name":"20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html"},{"name":"20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/515506/100/0/threaded"},{"name":"oval:org.mitre.oval:def:12514","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12514"},{"name":"http://www.microsoft.com/technet/security/advisory/2490606.mspx","refsource":"MISC","url":"http://www.microsoft.com/technet/security/advisory/2490606.mspx"},{"name":"http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt","refsource":"MISC","url":"http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt"},{"name":"http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg","refsource":"MISC","url":"http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-0347","datePublished":"2011-01-07T22:00:00.000Z","dateReserved":"2011-01-07T00:00:00.000Z","dateUpdated":"2024-08-06T21:51:08.493Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-01-07 23:00:20","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*","matchCriteriaId":"8682FAF3-98E3-485C-89CB-C0358C4E2AB0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*","matchCriteriaId":"E61F1C9B-44AF-4B35-A7B2-948EEF7639BD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"347","Ordinal":"1","Title":"CVE-2011-0347","CVE":"CVE-2011-0347","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"347","Ordinal":"1","NoteData":"Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz.","Type":"Description","Title":"CVE-2011-0347"},{"CveYear":"2011","CveId":"347","Ordinal":"2","NoteData":"2011-01-07","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"347","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}