CyberSec.Space Logo
Back to CVE Browser

CVE-2013-3897

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score82.9920%
EPSS Percentile92.66th
PublishedOct 9, 2013
Last ModifiedApr 22, 2026

Vulnerability Description

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."

Affected Platforms (CPE)

πŸ“¦
Microsoft

Internet Explorer

= 6
πŸ“¦
Microsoft

Internet Explorer

= 7
πŸ“¦
Microsoft

Internet Explorer

= 8
πŸ“¦
Microsoft

Internet Explorer

= 9
πŸ“¦
Microsoft

Internet Explorer

= 10
πŸ“¦
Microsoft

Internet Explorer

= 11

References & Advisories

Related Vulnerabilities