CVE-2010-3962
KEVHIGH 9.3EPSS 96.9%
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 96.89% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-10-06
- Published
- 2010-11-05
- Updated
- 2025-10-22
Proof-of-concept exploits (2)
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/16551
- https://www.exploit-db.com/exploits/15421
- https://www.exploit-db.com/exploits/15418