Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which allows remote attackers to obtain sensitive information from process memory via a crafted HTML document, aka "Null Byte Information Disclosure Vulnerability."
| Software | From | Fixed in |
|---|---|---|
| microsoft / internet_explorer | 7 | 7.x |
| microsoft / internet_explorer | 8 | 8.x |
| microsoft / internet_explorer | 9 | 9.x |