peter bassill · operator
$ cve CVE-2009-0076 JSON

CVE-2009-0076 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 33.5% (pctl 98)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS33.54% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2009-02-10
Last modified2026-06-16

Affected (5)

VendorProduct
microsoftinternet explorer
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD