CVE-2013-3897
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 9, 2013
Updated: Dec 19, 2024
CWE ID 416
Summary
CVE-2013-3897 is a use-after-free vulnerability affecting the CDisplayPointer class in Microsoft's mshtml.dll library, which is used by Internet Explorer 6 through 11. This issue arises when the browser fails to properly manage memory during the handling of crafted JavaScript code that employs the onpropertychange event handler. Attackers can exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition, as demonstrated in attacks in September and October 2013.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Internet Explorer
Affected Vendors
- Microsoft