← Back to browse · API

CVE-2011-0346

Severity
HIGH
CVSS
8.1
EPSS
0.31016
Risk score
43.26
CISA KEV
No
PoC
No
Published
2011-01-07
Modified
2024-10-21
First seen
2026-08-07
Aliases
EUVD-2011-0372, GHSA-P9R7-8RJP-GMW3
Products
n/a:n/a n/a
Sources
euvd EUVD-2011-0372

Description

Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka "MSHTML Memory Corruption Vulnerability."

References