CyberSec.Space Logo
CVEブラウザに戻る

CVE-2013-3897

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score82.9920%
EPSS Percentile92.66th
Published2013年10月9日
Last Modified2026年4月22日

Vulnerability Description

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."

Affected Platforms (CPE)

📦
Microsoft

Internet Explorer

= 6
📦
Microsoft

Internet Explorer

= 7
📦
Microsoft

Internet Explorer

= 8
📦
Microsoft

Internet Explorer

= 9
📦
Microsoft

Internet Explorer

= 10
📦
Microsoft

Internet Explorer

= 11

References & Advisories

関連する脆弱性情報