VYPR
Unrated severityNVD Advisory· Published Apr 8, 2008· Updated Apr 23, 2026

CVE-2008-1085

CVE-2008-1085

Description

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler.

Affected products

24
  • Microsoft/Ie7 versions
    cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:ie:7:*:windows_server_2003:*:*:*:*:*
    • cpe:2.3:a:microsoft:ie:7:windows_server_2003_sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:ie:7:windows_xp_sp2:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2:*:*:*:*:*+ 16 more
    • cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2_itanium:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2_itanium:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_itanium_edition:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_x32_edition:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2008_x64_edition:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista_x64:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.