CVE-2012-0012: Microsoft Internet Explorer

Medium severity, CVSS 4.3. EPSS: 16% chance of exploitation in the next 30 days.

Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."

Affected products

Published 2012-02-14. Last modified 2026-06-16.