Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-3897

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.888
EPSS Ranking 99.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.3
Proposed Action
A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
Ransomware Campaign
Unknown
Products affected by CVE-2013-3897


Contact Us

Shodan ® - All rights reserved