AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2008-2257

HIGH · CVSS 9.3 EPSS 35.22%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-08-13 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2008-2257
Severity
HIGH
CVSS
9.3
EPSS
35.22%
Microsoft

Original Filing — NVD Description

Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.