Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-07T10:31:27.906Z

Reserved: 2008-10-31T00:00:00

Link: CVE-2008-4844

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2008-12-11T15:30:00.393

Modified: 2025-04-09T00:30:58.490

Link: CVE-2008-4844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.