Vulnerability Details CVE-2013-3846
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CSpliceTreeEngine::InsertSplice object in an HTML document, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143 and CVE-2013-3161.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.331
EPSS Ranking 96.7%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2013-3846
-
cpe:2.3:a:microsoft:internet_explorer:10
-
cpe:2.3:a:microsoft:internet_explorer:9