50622 : Microsoft IE mshtml.dll XSML Nested SPAN Element Handling Unspecified Arbitrary Code Execution
Printer | http://osvdb.org/50622 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
21 2104 over 3 years ago about 1 year ago 33 times 90%

Timeline

Disclosure Date Vendor Solution Date
2008-12-10 2008-12-10

Keywords

JS_DLOAD.MD, c01634640, HPSBST02397, SSRT080187

Description

A use-after-free flaw exists in Internet Explorer. The data binding function fails to update the array length after releasing an object resulting in access to the deleted object's memory space. With a specially crafted web page, a context dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Commercial
Disclosure: Vendor Verified, Uncoordinated Disclosure, Discovered in the Wild
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Internet Explorer
Watch-list
5.01
6 SP1
7
6

References

Tools & Filters

Snort

15126
35221

Credit

Unknown or Incomplete

CVSSv2 Score

CVSSv2 Base Score = 9.3
Source: nvd.nist.gov | Generated: 2008-12-11 | Disagree?

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/01/21 00:50:19 | “Fully Stealthed” means fully spoofable

from: Blogs - MSMVPS.COM

[ Black Hole - you see it, because it isn't there!] ... Explorer patch MS08-078 is actually a conspiracy by Microsoft (and the government, of course

2009/01/19 05:10:00 | Fun Reading on Security and Compliance #11

from: SecurityRatty: Latest Articles

Instead of my usual "blogging frenzy" machine gun blast of short posts, I will just combine them into my new blog series " ... it! While you are reading it, check this one too (on webapp security “arriving”) “MS08-078 and the SDL”

2009/01/19 05:10:52 | Windows Workstation 2008 VII Powerd by Server 2008 SP1

from: The Unknownz

Windows Workstation 2008 VII Powerd by Server 2008 SP1 Bootable | ISO | 3.65 GB These are all pre regged now Disable Verbose mode Enable Explorer thumbnails Prevent Audio Stutter Enable Audio Service Disable ShutdownEventtracker Disable Control+Alt+Delete Added Office 2007 with SP 1 Changed Vmware to better version as new one does not work

2008/12/18 22:27:00 | Off-Cycle Internet Explorer Security Update Released

from: Microsoft News

As expected, Microsoft on Wednesday released its second out-of-cycle patch in three months -- this time to plug a widely discussed and "critical" vulnerability in Internet Explorer.This new patch, as described in Microsoft Security Bulletin MS08-078, is designed to thwart a remote code execution exploit that can occur if a user visits

2008/12/17 22:09:00 | MS08-078 Released to close Zero Day Exploit

from: Michael J. Murphy's WebLog

Microsoft strongly recommends our customers prepare their systems and networks to apply a security update immediately to help ensure that their computers are protected from attempted criminal attacks. For more information and the updates please visit http://www.microsoft.com/protect

2009/01/07 15:35:00 | All Browsers susceptible on Holiday Season

from: Computer Safety Tip

We never heard about security flaws in rival browsers to Internet Explorer, but this past week Firefox, Opera, and [ computer_by_lulu2000] ... rushed out Bulletin MS08-078, affecting IE 5.01-1E 7 and plugging up holes allowing for remote code

2008/12/23 20:18:16 | FireFox benefits from Internet Explorer 7 security flaw?

from: Strategic Internet Marketing Consultant UK | Blue Snapper

Following on from the report about the latest Internet Explorer 7 exploit, Microsoft has issued an ‘out-of-band’ (unscheduled to you and me…) security update for IE: MS08-078. This update is classified as critical for Internet Explorer 5.01, Internet Explorer 6, Internet Explorer 6 Service Pack 1 and Internet Explorer 7 as well

2008/12/21 16:52:00 | Serious security flaw found in Internet Explorer

from: The 8th Voyager

You might be awared that recently, there is a serious security flaw found in Internet Explorer versions 5.01, 6 and 7 ... Bulletin MS08-078 (KB-960714) published on 17 December 2008, and rated as Critical by Microsoft. Microsoft

2009/01/01 15:34:46 | All Browsers susceptible As Holiday Season Continues

from: Computer Safety Tip

We never heard about security flaws in rival browsers to Internet Explorer, but this past week Firefox, Opera, and Safari all got patched as well, ... strategy. Microsoft rushed out Bulletin MS08-078, affecting IE 5.01-1E 7 and plugging up holes allowing

2008/12/29 15:38:11 | Microsoft IE Critical Update

from: BSU Today :: Bemidji State University

Microsoft released critical update  MS08-078 to repair known security problems in Internet Explorer.  In order to repair the issue, we are recommending that all users of Internet Explorer run

2008/12/20 19:33:42 | Microsoft Security patch for IE

from: ITechLog Blog

Microsoft has released the security patch for Internet Explorer for all supported Operating Systems ... 1, and Internet Explorer 7…” Read in full: Microsoft Secure Bulletin ms08-078 Related Posts

2008/12/29 07:32:26 | Some dope on the IE bug

from: Technology News

Some dope on the IE bug December 29th, 2008 A Micorosoft insider Michael Howard, has posted some details as to how the bug came into place ... and Exposures (CVE) entry for this bug is CVE-2008-4844. Before I get started, I want to explain the goals

2008/12/23 05:00:07 | Psst, can I bug you?

from: Allan's Best Week Ever

Psst, can I bug you? eek! Can I bug you to read something? It is here; a short and insightful view into the Security Development Lifecycle at Microsoft and the mobilization to get MS08-078 out the door. And like me you'll probably hang around the SDL blog

2008/12/27 00:13:33 | SDL & MS08-078

from: Vulnerable Minds

I really enjoyed this article by the Microsoft Security Development Lifecycle team about how the SDL affected (or more importantly didn't affect) the recent IE 0-Day that gave a lot of people some sleepless nights recently. I may be becoming a Microsoft Security fanboy, even if I don't really like their OS

2008/12/18 19:46:04 | This Sunday in the Missoulian; update Internet Explorer

from: Songdog Tech, LLC

This Sunday in the Missoulian; update Internet Explorer December 18th, 2008 [ Glacial hills near Ovando][ enlarge] ... , which enables websites to plant malware and steal information. The patch is called MS08-078 (link

2008/12/18 18:26:46 | Microsoft patches critical IE bug with emergency update

from: BETTERANTIVIRUS.COM - Nod32, Security Threat and Virus News

Researchers give the company high marks for getting a fix out fast December 17, 2008 (Computerworld) As it promised yesterday, Microsoft Corp ... security bulletin MS08-078, fixes a flaw in the data-binding function of all available versions

2008/12/18 16:05:43 | Major Security Flaw Threatens Internet Explorer Users

from: Tech Gossip

Internet Explorer users are advised to switch to another browser until a major security flaw is fixed ... : MS08-078. It is labeled as critical, and everyone is instructed to install it. Technorati Tags

2008/12/18 15:45:18 | Microsoft Security Response Center Update on Internet Explorer 7 Exploit

from: Infosecurity.US: Information Security & Occasional Forays Into Other Realms

[ XP] Microsoft Corporations’ (NasdaqGS: MSFT) Security Response Center’s Director Mike Reavy has published an update detailing the Center’s ... Center MS08-078 Released Hello, Mike here, Today we released security update MS08-078, protecting

2008/12/18 15:38:00 | MS08-078 - Windows Update error 0x80072EE2 resolved on one PC

from: Blogs - MSMVPS.COM

MS08-078 - Windows Update error 0x80072EE2 resolved on one PC My corporate Dell XP SP3 laptop with IE7 updated fine and no issues have been seen so far Our family Dell XP SP3 Desktop with IE8 b2

2008/12/18 15:19:43 | Microsoft Releases Critical Internet Explorer Patch

from: Privacy Digest | News that can impact your privacy.

Microsoft Releases Critical Internet Explorer Patch: ... security update, MS08-078, to fix a vulnerability in its Internet Explorer Web browser that's being ... that they are not successful against customers who have applied the security update. MS08-078 has a maximum

2008/12/18 14:24:46 | Microsoft SMB Community Blog : Microsoft Security Bulletin MS08

from: Oops News

Microsoft SMB Community Blog : Microsoft Security Bulletin MS08 Hello, Mike here, Today we released security update MS08-078 , protecting customers from active attacks against Internet Explorer

2008/12/23 14:48:38 | W2K3 Server Services Stopping

from: Windows BBS

For the last couple of days a W2K3 server has been dropping network connections and refusing reconnects ... and the emergency Explorer fix, MS08-078. Attempting to map a network drive to the server results in: "The mapped

2008/12/23 07:34:41 | If you take security seriously…

from: .Net

If you take security seriously… December 23rd, 2008 Your Ad Here If you take security seriously… and you program in .Net then the following tools are must… Microsoft Anti-Cross Site Scripting Library V3.0 Beta - AntiXSS 3.0 helps you to protect your current applications from cross-site scripting attacks,

2008/12/23 06:49:13 | Internet Explorer: A Patchy Job!

from: Technology blog

Microsoft has issued a rare “off-schedule” security patch for its internet explorer browser versions 5,6,7 ... is available on the Microsoft website and is part of the MS08-078 security bulletin. The patch prevents

2008/12/22 19:35:00 | Windows 2000 - New version of Windows Update addresses 100 percent CPU issue

from: Harry Waldron - Corporate and Home Security

Travel I've been updating all work and home PCs for the critical Internet Explorer security patch (MS08-078). During this process, I've encountered a new version of Windows Update which

2008/12/22 17:33:48 | IE Users Beware

from: Research Blog - Research - SecureWorks

IE Users Beware December 22nd, 2008 by Melinda Rosario On December 9, 2008, a “weaponized” zero-day exploit for a previously undisclosed vulnerability in Microsoft Internet Explorer 7 was discovered in the wild being used by Chinese hackers to install malware on victims’ computers

2008/12/22 06:12:09 | Microsoft’s emergency patch for IE

from: Bangladeshi Blogs Websites History, Article, News, Research, Information, Industry Business Stories News

Microsoft on Wednesday released an emergency patch to fix a perilous software flaw allowing hackers to hijack Internet Explorer browsers and take over computers. The US software giant said security update MS08-078 addresses a vulnerability cyber-criminals can exploit to their advantage. “Microsoft encourages all IE customers to test

2008/12/21 14:52:02 | how to stop Word documents being used in new attacks on IE XML flaw

from: read tips which will make your tasks easier and will keep you safe

Friends, as you all know about a new security flaw in IE, The list of things to worry about with the soon-to-be-patched MS08-078 XML data binding vulnerability  is getting longer by the minute.  The researchers at McAfee’s AVERT Labs report

2008/12/21 05:56:00 | Another Out Of Band MS08-078

from: Admin Anonymous

This is going to be short as it's already covered well elsewhere and this is late... Microsoft has another out-of-band patch as of 12/17, MS08-078 affecting all versions of IE on all supported OSes except Server 2008 for IA-32/x64. Zero-day exploits are already going

2008/12/21 05:36:20 | Install This Microsoft Security Patch to Avoid a Dangerous Flaw

from: Jason Ciment’s Blog on Secrets of the Innovative Mind

http://www.jasonciment.com/jason-thoughts/microsoft-security-patch-dec2008/. I got this from a great and knowledgeable web security expert Oli Thordarson at Alvaka networks tonight:   *** ENSURE MS08-078 IS APPLIED TO ALL WORKSTATIONS AND SERVERS ASAP *** http

2008/12/19 16:28:14 | Security News Roundup: Spam to hit record levels in 2009

from: IT Security | TechRepublic.com

This week’s security events include news of Microsoft, Mozilla, and Opera releasing patches for their respective browsers, ... MS08-078. On the same day, Mozilla have also updated its popular Firefox browser to version 3.0.5 mid

2008/12/17 20:23:24 | Get your Microsoft Flu Shot IE patch here!

from: The Sillican Files

Everyone wait in line, for Microsoft is patching for the latest and greatest exploit of the year ... Vulnerability - CVE-2008-4844. Resources: • You can provide feedback by completing the form

2008/12/19 04:39:00 | MS08-078 and the SDL

from: Thoughts of a Technocrat

Via Microsoft SDL Blog -Hi, Michael here. Every bug is an opportunity to learn, and the security update that fixed the data binding bug that affected Internet Explorer users is no exception. The Common Vulnerabilities and Exposures (CVE) entry for this bug is CVE-2008-4844

2008/12/19 02:41:09 | Microsoft patches critical IE bug with emergency update

from: Article

As it promised yesterday, Microsoft Corp. today issued an emergency patch to plug a critical hole in Internet Explorer (IE) that attackers have been increasingly exploiting from hacked Web sites. The patch, described in Microsoft's security bulletin MS08-078, fixes a flaw in the data-binding function of all available

2008/12/19 02:08:00 | MS Critical Update for Internet Explorere [Dec 17 2008]

from: India Broadband Forum

Microsoft has released a critical security update to resolve the vulnerability in Internet Explorer that attackers began targeting last week ... who do not have Automatic updates enabled Microsoft Security Bulletin MS08-078 - Critical

2008/12/20 04:51:34 | Microsoft’s emergency patch for IE

from: Bangladeshi Blogs Websites History, Article, News, Research, Information, Industry Business Stories News

Microsoft on Wednesday released an emergency patch to fix a perilous software flaw allowing hackers to hijack Internet Explorer browsers and take over computers.The US software giant said security update MS08-078 addresses a vulnerability cyber-criminals can exploit to their advantage.”Microsoft encourages all IE customers to test and deploy

2008/12/19 22:26:00 | Microsoft Issues Security Patch For Internet Explorer

from: StarterTech.com

[ Internet Explorer logo]All users of Internet Explorer need to update immediately to fix a critical security hole ... site and will find it is part of Microsoft’s security bulletin MS08-078. While it is good news

2008/12/19 16:52:59 | "The list of things to worry about with the soon-to-be-patched MS08-078 XML data binding..."

from: Quasi.Tumblr.

“The list of things to worry about with the soon-to-be-patched MS08-078 XML data binding vulnerability is getting longer by the minute. The researchers at McAfee’s AVERT Labs report

2008/12/19 14:31:15 | Microsoft patches critical IE7 flaw

from: Limebox Hosting Solutions Portal

Microsoft issued an out-of-band emergency patch Wednesday for a zero-day Internet Explorer vulnerability that has opened the door for hackers to ... after the release of Windows IE 8 Beta 2, but Microsoft still recommends in its MS08-078 advisory

2008/12/19 11:34:12 | Security Update for Internet Explorer (960714)

from: Lacou - I.T and Design Agency

We have been following this story for you since it was first said by Microsoft that they were experiencing some security flaws in Internet Explorer ... effect.See full story below: See full story below: Microsoft Security Bulletin MS08-078

2008/12/19 11:08:00 | Microsoft has released a fix for the IE security hole

from: Technology - Technology - Computers, Internet, Software, Personal Tech, consumer electronics,and wireless technology.News

Following the direful invoke of message agitated by the past zero-day section flaw, Microsoft has hurried discover a patch. The protective you domain is: Microsoft Security Bulletin MS08-078 - Critical Security Update for cyberspace Explorer (960714) Look finished the plateau of Affected Software to encounter

2008/12/19 10:15:26 | [MS Security Bulletin] Minor Revisions Dec 19th 08

from: Cliff Hobbs - FAQShop.com and Microsoft MVP ConfigMgr/ SMS

Summary ======= The following bulletins have undergone a minor revision increment. Please see the appropriate bulletin for more details. * MS08-078 - Critical Bulletin Information: =============== * MS08-078 - Critical - http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx - Reason for Revision: V1.1 (December 18

2008/12/19 10:15:26 | [MS Security Bulletin] Minor Revisions Dec 19th 08

from: Blogs - MSMVPS.COM

[MS Security Bulletin] Minor Revisions Dec 19th 08 Summary ======= The following bulletins have undergone a minor revision increment. Please see the appropriate bulletin for more details. * MS08-078 - Critical Bulletin Information: =============== * MS08-078 - Critical - http://www.microsoft.com/technet... Posted to Cliff Hobbs

2008/12/19 09:01:00 | Microsoft Security Bulletin Minor Revisions - December 18, 2008

from: Blogs - MSMVPS.COM

Issued: December 18, 2008 Summary The following bulletins have undergone a minor revision increment. Please see the appropriate bulletin for more details. * MS08-078 - Critical Bulletin Information: * MS08-078 - Critical - http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx

2008/12/19 08:15:17 | Security: Mozilla Patch/Update

from: leedesmond’s blog

Security: Mozilla Patch/Update Dec 19th 2008webmasterSecurity On the heals of Microsoft’s MS08-078 security advisory, Mozilla Foundation has also released security updates - some critical

2008/12/19 05:58:57 | Microsoft Releases Critical Internet Explorer Patch

from: technichristian.net

Microsoft has released an out-of-band security update, MS08-078, ... against customers who have applied the security update. MS08-078 has a maximum severity rating

2008/12/19 05:15:33 | Internet Explorer 7 Security issue fix KB960714

from: SmartAdmin- Weblog for Technical Tips, Online Tutorials and Free Tools

Microsoft has officially released the Internet Explorer patch to fix the security flaw affecting all versions of the browser. IE Patch KB960714 The IE patch can be downloaded from the Microsoft Update site. It is part of Microsoft’s security bulletin MS08-078 and is under the code KB960714. The fix functions as an IE7

2008/12/19 03:27:56 | Fix Available for Microsoft IE Security Flaw

from: Techtwister

Microsoft Security Bulletin MS08-078 - Critical Security Update for Internet Explorer (960714) http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx Read Computerworld’s article

2008/12/19 03:21:25 | DOWNLOAD: Critical Security Update for Internet Explorer 5/6/7 released (MS08-078)

from: Kurt Shintaku's Blog - Windows Live

There are active threats floating around out there on web sites right now.  It’s so important that we’ve released this patch out-of-band, i.e. we didn’t wait until the next “patch Tuesday”. Please strongly consider deploying this patch to your users.  Seriously.  No joke. Microsoft Security Bulletin MS08-078 – Critical Security Update

2008/12/19 03:18:42 | Microsoft patches IE hole

from: Macsmind Official Blog of the MacRanger Show, News and Insights

As you might have heard Microsoft’s Internet Explorer has suffered yet another exploit ... MS08-078, fixes a flaw in the data-binding function of all available versions of the popular browser

2008/12/18 04:13:12 | Emergency Security Update for Internet Explorer (KB960714) Is Available Now

from: The Winhelponline Blog - Troubleshooting Information, Tips and Fixes for Microsoft Windows

A serious security vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, ... 2008. (REF CVE-2008-4844) Microsoft has released a Security Update for Internet Explorer (960714

2008/12/17 21:22:39 | Microsoft releases off-cycle critical security patch for Internet Explorer

from: Wekti.com | Tech News and Opinion

[ oops] Microsoft has released an off-cycle patch for a previously known vulnerability in Internet Explorer which would’ve allowed virus and malware ... : CVE-2008-4844. Patch details from Microsoft: MS08-078. This could be a good opportunity for Google

2008/12/17 21:06:55 | KB960714:MS08-078 Internet Explorer Security Update

from: Technology | Tech | Gadget | Tech.Spreadit.org - News And Reviews, With Pictures, Of Games, Gadgets,& Technology

KB960714:MS08-078 Internet Explorer Security Update - KB960714 has been released to solve THE IE Problem/IE Vulnerability that has been occurring in ... (CVE-2008-4844). The patch, to be released on December 17, will ...

2008/12/17 20:46:42 | It’s official: MS08-78 fixing critical IE bug

from: Security and the Net

Microsoft just released MS08-78, a security bulletin describing the issue that has been affecting Internet Explorer users for almost a week ( ... CVE-2008-4844). The bug is fixed for Internet Explorer 5.01, 6, 7 and the beta version of IE8. As Microsoft points out on their Internet Explorer homepage, the browser is now “safer than ever”. Don’t ...

2008/12/17 18:51:04 | Microsoft Security Advisory (961051): Vulnerability in Internet Explorer Could Allow Remote Code Execution - 12/17/2008

from: Namibia Community - The Shebeen

Revision Note: December 17, 2008: Advisory updated to reflect publication of security bulletin ... addressed is the Microsoft XML Core Services Vulnerability - CVE-2008-4844. More...

2008/12/17 02:01:02 | Microsoft to Release KB961051 on the Dec 17, 2008

from: Tech-Linkblog.com

According to McAfee and I will quote: December 16, 2008: Microsoft has announced an out-of-cycle patch release for a critical, remote-code-execution, vulnerability in Microsoft Internet Explorer (CVE-2008-4844). The patch, to be released on December 17, will address the vulnerability across multiple versions on Internet

2008/12/16 21:08:12 | CSA 6.0 Policy in Action (CVE-2008-4844 - Internet Explorer XML Handling 0-day exploit)

from: Priveon Labs Security Blog

In case you've been vacationing in the jungles of Borneo, ... /cvename.cgi?name=CVE-2008-4844 MS Advisory: http://www.microsoft.com

2008/12/13 18:35:00 | IE vulnerability just one of many

from: Eating Security

The latest IE "0day" is making big news. The bulletin now includes IE6, IE7, and IE8 beta. Looking at CVE-2008-4844 will give a decent round-up of related links. Shadowserver has a list of domains known to be using exploits that attack this vulnerability. Microsoft has some workarounds

2008/12/18 01:52:39 | IE 7 Patch

from: - Technibble - A Resource for Computer Repair Technicians & to get PC tech support help.

Microsoft released a patch today for Internet Explorer version 7 ... that they are not successful against customers who have applied the security update. MS08-078 has a maximum severity

2008/12/18 01:42:04 | Here’s an Out of Band Critical Update for IE (MS08-078) [960714]

from: Christopher Kusek, Technology Evangelist

For those of you who have not seen this newly released Out of Band Critical Security Update, you should check out MS08-078 What does this mean exactly? Here is Microsoft’s Take: Executive Summary This security update resolves a publicly disclosed vulnerability. The vulnerability could

2008/12/18 01:33:32 | Critical IE vulnerability

from: Blogs - Partner Blog Community

As I related in my previous post, even though IE may not be the most (or even one of the top 10) ... that as emergency) security update MS08-078 to address a new vulnerability allowing remote code execution in affected versions of Internet Explorer. MS08-078 has a maximum severity rating of Critical

2008/12/18 01:28:46 | Microsoft Security Advisory MS08-078 - time to patch

from: WOT-NOTARY

Today December 17, 2008 Microsoft has released a critical security patch for Internet Explorer 5,6,7, and 8 Beta 2 ... . From the New Microsoft Security Advisory MS08-078 This alert is to provide you with an overview ... has released security bulletin MS08-078, Security Update for Internet Explorer (960714), to address

2008/12/18 13:37:50 | Microsoft Issues Emergency Patch For Internet Explorer

from: dBTechno

[ Microsoft lived up to their word and issued an emergency patch for Internet Explorer on Wednesday<br /> .....]Washington (dbTechno) ... and is talked about in security bulletin MS08-078. Many are applauding Microsoft for getting the patch

2008/12/18 13:28:22 | Microsoft patches critical IE bug with emergency update

from: Blogger Indonesia A. Fatih Syuhud Weblog

Computerworld notes: As it promised yesterday, Microsoft Corp. today issued an emergency patch to plug a critical hole in Internet Explorer (IE) that attackers have been increasingly exploiting from hacked Web sites. The patch, described in Microsoft’s security bulletin MS08-078, fixes a flaw in the data-binding function of all available

2008/12/18 13:21:38 | KB960714, MS08 078, Microsoft Internet Explorer Security Update

from: FAQ

KB960714, MS08 078, Microsoft Internet Explorer Security Update It is part of Microsoft’s security bulletin MS08-078 and is under the code ... bulletin MS08-078 and is under the code KB960714. The fix functions as an IE7 patch as well as one for IE5 ... Internet Explorer Patches(KB960714) MS08-078, System Requirements, Supported Operating Systems

2008/12/18 13:13:00 | Internet explorer flaw fixed.....

from: Techno-entertainment blog

A quick update to our earlier post about the recent critical vulnerability (MS08-078) in all available versions of Internet Explorer — Microsoft has released an update patch for the vulnerability

2008/12/18 11:44:05 | Security: Critical IE Patch (out-of-band MS08-078)

from: leedesmond’s blog

Security: Critical IE Patch (out-of-band MS08-078) Dec 18th 2008webmasterSecurity &amp; ... vulnerability (various versions), you should immediately review MS08-078 and KB960714 and take

2008/12/18 10:26:44 | hayy thank you!

from: Always be a part of me

Microsoft release Patch for INTERNET EXPLORER!!! SAN FRANCISCO (AFP) ... security update MS08-078 addresses a vulnerability cyber-criminals can exploit to their advantage. read

2008/12/18 06:41:59 | Microsoft released patch for the deadliest IE vulnerability

from: MERO GUFF - Blog on Information Technology,Fun,reviews,Mobiles,Computer related to NEPAL

A serious Internet Explorer flaw could allow attackers to gain access of computer using remode-code-execution methods. Yesterday, Microsoft announced to release the fix and here it's the fix for the problem. Click the link below to download the latest IE7/IE6/IE5 Vulnerability patch. MS08-078 - addresses

2008/12/18 06:25:48 | Microsoft released KB960714 to fix THE IE Problem

from: Maratechnology.com

Microsoft released KB960714 to fix THE IE Problem Where to Find the IE Patch (KB960714)? ... Update site. It is part of Microsoft’s security bulletin MS08-078 and is under the code KB960714

2008/12/18 06:11:41 | Get The Latest Security Updates For Mozilla Firefox And Internet Explorer

from: Web Developer Blog - Downloadtube.com

Critical security updates were released for both Mozilla Firefox and Internet Explorer web browsers. In case of Internet Explorer browser, the MS08-078 security update solves the vulnerability found in versions 5.01, 6, 6 Service Pack 1, 7 and 8 beta 2. The security flaw patched by this update

2008/12/18 05:45:56 | Microsoft, Mozilla Release Browser Fixes: Get The Download Patches Here

from: Microsoft, Mozilla Release Browser Fixes: Get The Download Patches Here SEO SEORANG lah SEORANG dong

Microsoft, Mozilla Release Browser Fixes: Get The Download Patches Here Posted by seorangs It’s been a week of browser security holes and ... patch, coded KB960714 and part of Security Bulletin MS08-078, is considered a critical update

2008/12/18 05:39:27 | MS08-078 - Critical Internet Explorer security update now

from: Oops News

MS08-078 - Critical Internet Explorer security update now Hello, Mike here, Today we released security update MS08-078 , protecting customers from active attacks against Internet Explorer

2008/12/18 04:29:17 | Microsoft patches critical IE bug with emergency update

from: India Broadband Forum

Microsoft patches critical IE bug with emergency update Quote: Internet Explorer users at risk of hacking: ... . The patch, described in Microsoft's security bulletin MS08-078 , fixes a flaw in the data binding function

2008/12/18 04:03:49 | Urgent Update of Internet Explorer - Install It Now

from: Just a Coder - nickfitz.co.uk

Urgent Update of Internet Explorer - Install It Now December 18th, 2008 Given that I’m so prone to criticising Microsoft, I have to give them credit for moving so rapidly to provide a patch for the recently discovered vulnerability in Internet Explorer

2008/12/18 03:29:08 | Internet Explorer Security Flaw

from: On-Site Computer Solutions Evansville Indiana News

Internet Explorer Security Flaw December 17th, 2008 A serious vulnerability in Microsoft Internet Explorer has been patched today. This vulnerability allowed for saved internet passwords to be stolen using malicious code.   Microsoft considers this risk critical enough to release a patch outside of their regular patch schedule

2008/12/18 02:04:00 | Critical Out Of Band Hotfix for IE Released

from: The Lazy Admin

Typically hotfixes are released on the second Tuesday of each month as you are all well aware ... Security Bulletin MS08-078 – Critical Security Update for Internet Explorer (960714) http

2008/12/18 01:55:32 | Security Bulletin MS08-078 - Security update for Internet Explorer

from: Advertiseri din Romania care au ales sa'si faca reclama direct la mine ; Megadeth Hangar 18 - YouTube Gallery ; Security Bulletin MS08-078 - Security update for Internet Explorer

Security Bulletin MS08-078 - Secu... Microsoft has released security bulletin MS08-078. Security update 960714 packages for Windows XP & for Windows Server 2003 include Internet Explorer hotfix

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use