CVE-2013-3897
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
Affected (6)
Products: Microsoft: Internet Explorer
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2003 | All versions |
Microsoft Windows Server 2008 | Version r2 sp1 |
Microsoft Windows Xp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Microsoft Windows Vista | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 7 | All versions |
Microsoft Windows 8 | All versions |
Microsoft Windows Server 2008 | Version r2 sp1 |
Microsoft Windows Server 2012 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 8.1 | All versions |
Microsoft Windows Rt 8.1 | All versions |
Microsoft Windows Server 2012 | Version r2 |
References (9)
Source: secure@microsoft.com
Broken LinkVendor Advisory
Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.