CVE-2010-3886

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
08/10/2010
Last modified:
11/04/2025

Description

The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*