Difference between revisions of "CVE-2013-3897"
(Created page with "{{Vuln}}") |
|||
Line 1: | Line 1: | ||
{{Vuln}} | {{Vuln | ||
|Description=Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability." | |||
|target=Microsoft Internet Explorer | |||
}} |
Latest revision as of 22:36, 20 July 2015
MITRE CVE Reference: CVE-2013-3897
Description: Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
Usage
Targetted asset: Microsoft Internet Explorer
Exploit kits using this vulnerability/ Exploit kits utilisant cette vulnérabilité:
- Exploit kits: Gong Da
Botnets using this vulnerability to function/propagate:
- Botnets:
Campaigns using this vulnerability:
- Campaigns:
Packages includingthis vulnerability:
- Packages:
Publications
Author | Editor | Year | |
---|---|---|---|
An overview of exploit packs | Mila Parkour | Contagio | 2012 |
MITRE CVE LICENSE: The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use Common Vulnerabilities and Exposures (CVE®) for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE’s copyright designation and this license in any such copy. MITRE CVE®, TERMS OF USE: [1]