VULNERABILITY INTELLIGENCE

CVE-2011-1256

CVSS score9.3 HIGH
EPSS probability18.65%
CISA KEVNot currently listed
Published2011-06-16
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Modification Memory Corruption Vulnerability."

Weakness classification

  • CWE-908: Use of Uninitialized Resource

Primary references