Skip to main content

CVE-2008-4844

CVSS Score Not Available
82.85%
HIGH RiskEPSS (99th percentile)

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.

Published: 12/11/2008
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

82.85%HIGH Exploitation Risk
99th percentile

This vulnerability has a 82.85% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.