Skip to content

Instantly share code, notes, and snippets.

@h0wl
Created June 7, 2015 08:23
ie11 getinputcontext windbg
(4684.4fcc): Access violation - code c0000005 (!!! second chance !!!)
eax=00000000 ebx=0e2b6f84 ecx=00000000 edx=0a8e7fb8 esi=00000000 edi=0e2b6e98
eip=5f302e86 esp=0a84b074 ebp=0a84b098 iopl=0 nv up ei pl zr na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010246
MSHTML!Tree::ElementNode::GetCElement:
5f302e86 f7410800001000 test dword ptr [ecx+8],100000h ds:002b:00000008=????????
0:017> .symfix
0:017> .reload
Reloading current modules
................................................................
...........................
0:017> kb
ChildEBP RetAddr Args to Child
0a84b070 5f9e4857 00000001 0e2b6e98 0a84b0ac MSHTML!Tree::ElementNode::GetCElement
0a84b080 5f474190 00000001 00000000 0a8d1fc8 MSHTML!CTsfTextStore::Initialize+0x8c
0a84b098 5f474108 00000001 00000000 0a8d1fc8 MSHTML!TSmartPointer<CTsfTextStore>::Create<CElement *>+0x4f
0a84b0b0 5f476fed 00000001 00000000 09445840 MSHTML!CTsfTextStore::CreateForElement+0x15
0a84b0cc 5f476f6e 00000000 00001049 0a84b0ec MSHTML!CElement::Var_msGetInputContext+0x4a
0a84b0f8 5d05eeee 09445840 02000001 09440330 MSHTML!CFastDOM::CHTMLElement::Trampoline_msGetInputContext+0x3e
0a84b158 5d0e579b 09445840 02000001 09440330 jscript9!Js::JavascriptExternalFunction::ExternalFunctionThunk+0x101
0a84b1ac 5d0e5811 08ca206e 09445840 00000000 jscript9!Js::InterpreterStackFrame::OP_CallCommon<Js::OpLayoutDynamicProfile<Js::OpLayoutCallI_OneByte> >+0xd7
0a84b3a0 5d0e5977 06ae94f3 0a84b5d0 08ca204c jscript9!Js::InterpreterStackFrame::Process+0x228b
0a84b3d8 5d0e59d6 0a84b5bc 08ca2054 0a84b5d0 jscript9!Js::InterpreterStackFrame::OP_TryCatch+0x49
0a84b5c8 5d05cd0b 08ca2074 09165120 08ca2000 jscript9!Js::InterpreterStackFrame::Process+0x39dc
0a84b6f4 093c0fd9 0a84b708 0a84b8f8 5d05c5cd jscript9!Js::InterpreterStackFrame::InterpreterThunk<1>+0x1ce
WARNING: Frame IP not in any known module. Following frames may be wrong.
0a84b700 5d05c5cd 09109ce0 10000001 09163180 0x93c0fd9
0a84b8f8 5d05cd0b 08ca704a 09165360 08ca7000 jscript9!Js::InterpreterStackFrame::Process+0x1940
0a84ba1c 093c0fe1 0a84ba30 0a84ba70 5d05866d jscript9!Js::InterpreterStackFrame::InterpreterThunk<1>+0x1ce
0a84ba28 5d05866d 09109d60 00000002 09163180 0x93c0fe1
0a84ba70 5d058da5 00000002 0a84bbfc 06ae9dcf jscript9!Js::JavascriptFunction::CallFunction<1>+0x91
0a84bae4 5d058cdf 055178b8 00000002 0a84bbfc jscript9!Js::JavascriptFunction::CallRootFunction+0xc1
0a84bb2c 5d058c5f 0a84bb54 00000002 0a84bbfc jscript9!ScriptSite::CallRootFunction+0x42
0a84bb5c 5d05d490 09109d60 0a84bb84 00000000 jscript9!ScriptSite::Execute+0x61
0a84bbb8 5d05d3cc 00000002 0a84bbfc 00000000 jscript9!ScriptEngineBase::ExecuteInternal<0>+0xbb
0a84bbd0 5f64834c 054c5de0 09109d60 00000002 jscript9!ScriptEngineBase::Execute+0x1c
0a84bc8c 5f6481e6 09109d60 10d32fa0 10e70fc0 MSHTML!CListenerDispatch::InvokeVar+0x15a
0a84bcb8 5f647eb2 10d32fa0 10e70fc0 0a84be68 MSHTML!CListenerDispatch::Invoke+0x6d
0a84bd58 5f648056 0a84be68 00000001 10d32fa0 MSHTML!CEventMgr::_InvokeListeners+0x1fe
0a84bd70 5f647f43 10d32fa0 00000000 00000001 MSHTML!CEventMgr::_InvokeListenersOnWindow+0x42
0a84be00 5f4056d8 0a84be68 00000000 10d32fa0 MSHTML!CEventMgr::_InvokeListeners+0x13e
0a84bf80 5f40914f 00000000 ffffffff 00000000 MSHTML!CEventMgr::Dispatch+0x371
0a84bfa8 5f4f8afd 10f4cfe0 ffffffff 0dc60f68 MSHTML!CEventMgr::DispatchEvent+0x90
0a84bfe0 5f4f85e9 0a84c048 5f2ec860 0a89dbb8 MSHTML!COmWindowProxy::Fire_onload+0x146
0a84c040 5f4f8239 0d984bd0 0ef3cf48 0d984bec MSHTML!CMarkup::OnLoadStatusDone+0x373
0a84c054 5f4f7500 00000004 0dcbaf98 0a84c4b4 MSHTML!CMarkup::OnLoadStatus+0xfa
0a84c498 5f4e3a72 10000019 0a84c4f0 5f2ed385 MSHTML!CProgSink::DoUpdate+0x4c7
0a84c4a4 5f2ed385 0ef3cf48 0ef3cf48 0d8ebcc8 MSHTML!CProgSink::OnMethodCall+0x12
0a84c4f0 5f2eccaa 0691c273 00000000 5f2ebe80 MSHTML!GlobalWndOnMethodCall+0x16d
0a84c540 76b462fa 00020520 00008002 00000000 MSHTML!GlobalWndProc+0x2e5
0a84c56c 76b46d3a 5f2ebe80 00020520 00008002 user32!InternalCallWinProc+0x23
0a84c5e4 76b477c4 00000000 5f2ebe80 00020520 user32!UserCallWinProcCheckWow+0x109
0a84c644 76b4788a 5f2ebe80 00000000 0a84f820 user32!DispatchMessageWorker+0x3bc
0a84c654 6065e0f8 0a84c694 09f6ce48 0a220fe0 user32!DispatchMessageW+0xf
0a84f820 60692858 0a84f8ec 606924d0 09f6eff0 IEFRAME!CTabWindow::_TabWindowThreadProc+0x464
0a84f8e0 7502e51c 09f6ce48 0a84f904 606ed630 IEFRAME!LCIETab_ThreadProc+0x37b
0a84f8f8 74633991 09f6eff0 00000000 00000000 iertutil!_IsoThreadProc_WrapperToReleaseScope+0x1c
0a84f930 76c4336a 09a94fe8 0a84f97c 774692b2 IEShims!NS_CreateThread::DesktopIE_ThreadProc+0x94
0a84f93c 774692b2 09a94fe8 7ee4ba15 00000000 kernel32!BaseThreadInitThunk+0xe
0a84f97c 77469285 74633900 09a94fe8 ffffffff ntdll!__RtlUserThreadStart+0x70
0a84f994 00000000 74633900 09a94fe8 00000000 ntdll!_RtlUserThreadStart+0x1b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment