Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which allows remote attackers to obtain sensitive information from process memory via a crafted HTML document, aka "Null Byte Information Disclosure Vulnerability."
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-037
No PoCs found on GitHub currently.