Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
| Software | From | Fixed in |
|---|---|---|
| microsoft / internet_explorer | 6 | 6.x |
| microsoft / internet_explorer | 7 | 7.x |
| microsoft / internet_explorer | 8 | 8.x |
| microsoft / internet_explorer | 9 | 9.x |