CVE-2010-3971 is a critical use-after-free vulnerability in the CSharedStyleSheet::Notify function of the mshtml.dll CSS parser, affecting Microsoft Internet Explorer versions 6 through 8 and other products. This flaw allows remote attackers to execute arbitrary code or cause a denial of service via a specially crafted, self-referential @import rule within a stylesheet. With a CVSS score of 9.3, it is highly severe, requiring no authentication and moderate attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including a Metasploit module, and while not on the KEV catalog, it has garnered significant community discussion and media coverage, indicating its historical importance and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.