CVE-2015-2482
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted replace operation with a JavaScript regular expression, aka "Scripting Engine Memory Corruption Vulnerability."
- Affected products
- Internet Explorer, Jscript, Vbscript
- Microsoft Jscript
- = 5.6, 5.7, 5.8
- Microsoft Vbscript
- = 5.6, 5.7, 5.8
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 32.3% (98th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2015-10-14
CVE-2015-2482 at NVD
4 known exploits for CVE-2015-2482
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Internet Explorer 8 jscript - 'RegÂExpÂBase::FBadÂHeader' Use-After-Free (MS15
Microsoft Internet Explorer 8 - jscript 'RegÂExpÂBase::FBadÂHeader' Use-After-Free (MS15-018)
Microsoft Internet Explorer 8 Javascript RegExpBase::FBadHeader Use-After-Free
JScript 5.7 RegExpBase::FBadHeader Use-After-Free