CVE detail
CVE-2015-2502
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
Malicious actors have leveraged the critical Internet Explorer vulnerability patched by Microsoft on Tuesday to deliver a piece of malware through various legitimate websites, including the one of a Hong Kong church.
newswww.securityweek.comAug 20, 2015, 10:19 AM- Critical Zero-Day flaw – Microsoft Pushes Emergency IE PatchSecurity Affairs
Microsoft has pushed an emergency patch to remediate a zero-day vulnerability in Internet Explorer that is actively being exploited in-the-wild. Today, August 18th, 2015, Microsoft released an emergency patch after being notified of a critical vulnerability in all supported versions of Internet Explorer. All versions of Microsoft Internet Explorer from IE7 to IE11 are affected by this zero-day vulnerability. […]
newssecurityaffairs.comAug 19, 2015, 6:57 AM - Microsoft issues emergency patch for IE flaw exploited in the wildHelp Net Security
Microsoft has pushed out an emergency out-of-band Internet Explorer update, which fixes a critical memory corruption vulnerability (CVE-2015-2502) that is being actively exploited in attacks in the wild.“All version of Internet Explorer v7-v11 are affected. Users of the new Edge Browser on Windows 10 are not affected,” says Qualys CTO Wolfgang Kandek.“This vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user,” Microsoft … More →
newswww.helpnetsecurity.comAug 19, 2015, 2:47 AM Microsoft issued an emergency out-of-band update on Tuesday to fix a critical vulnerability (CVE-2015-2502) being actively exploited in the wild and affecting all versions of Internet Explorer from IE 7 through 11.
newswww.securityweek.comAug 18, 2015, 10:25 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2017-0149CVSS 8.8 · High
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Ex…
- CVE-2016-0189CVSS 7.5 · High
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code…
- CVE-2020-0878CVSS 4.2 · Medium
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an at…
- CVE-2020-1380CVSS 7.8 · High
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a…
- CVE-2020-0968CVSS 7.5 · High
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerabi…
- CVE-2019-1429CVSS 7.5 · High
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerabi…