← Back

CVE-2013-3846

nvd nist
Published: Dec 29, 2013Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CSpliceTreeEngine::InsertSplice object in an HTML document, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143 and CVE-2013-3161.

Affected (2)

1 product
Internet Explorer
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 10
Version 9

Related CWEs

Timeline

No history available yet.