CVE-2013-3897

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 9, 2013
Updated: Dec 19, 2024
CWE ID 416

Summary

CVE-2013-3897 is a use-after-free vulnerability affecting the CDisplayPointer class in Microsoft's mshtml.dll library, which is used by Internet Explorer 6 through 11. This issue arises when the browser fails to properly manage memory during the handling of crafted JavaScript code that employs the onpropertychange event handler. Attackers can exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition, as demonstrated in attacks in September and October 2013.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Internet Explorer

Affected Vendors

  • Microsoft