Back

CVE-2008-0077

HIGH

Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."

Published: Feb 12, 2008 Modified: Apr 23, 2026
CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: REQUIRED Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
microsoft internet_explorer 6
microsoft internet_explorer 6
microsoft internet_explorer 7

GitHub Security Advisory GHSA-mf54-6363-29h5

Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote...

Risk Scores

CVSS Score 8.8 / 10
EPSS Score 62.27%

Top 2% most likely to be exploited

Threat Score 53.9 / 100

Data Sources

NVD EPSS GitHub