peter bassill · operator
$ cve CVE-2009-3019 JSON

CVE-2009-3019 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 17.4% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and then calls setAttribute to set the value attribute.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS17.37% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2009-08-31
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftinternet explorer
microsoftwindows vista
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD