Executive Summary

Informations
NameCVE-2013-1306First vendor Publication2013-05-14
VendorCveLast vendor Modification2018-10-12

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score9.3Attack RangeNetwork
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score8.6AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1313.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1306

CWE : Common Weakness Enumeration

%idName
100 %CWE-416Use After Free

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:16398
 
Oval ID: oval:org.mitre.oval:def:16398
Title: Internet Explorer Use After Free Vulnerability - (CVE-2013-1306) MS13-037
Description: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1313.
Family: windows Class: vulnerability
Reference(s): CVE-2013-1306
Version: 5
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Product(s): Microsoft Internet Explorer 9
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application1

ExploitDB Exploits

idDescription
2013-06-13MS13-009 Microsoft Internet Explorer COALineDashStyleArray Integer Overflow
2013-06-07Microsoft Internet Explorer textNode Use-After-Free

Snort® IPS/IDS

DateDescription
2014-11-16Microsoft Internet Explorer CSS .ipsum layout use-after-free attempt
RuleID : 31585 - Revision : 3 - Type : BROWSER-IE
2014-11-16Microsoft Internet Explorer CSS .ipsum layout use-after-free attempt
RuleID : 31584 - Revision : 3 - Type : BROWSER-IE
2014-03-15Microsoft Internet Explorer 8 deleted object access via timer memory corrupti...
RuleID : 29803 - Revision : 3 - Type : BROWSER-IE
2014-03-15Microsoft Internet Explorer 8 deleted object access via timer memory corrupti...
RuleID : 29802 - Revision : 3 - Type : BROWSER-IE
2014-03-06Microsoft Internet Explorer VML array with negative length memory corruption ...
RuleID : 29602 - Revision : 3 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer 8 deleted object access via timer memory corrupti...
RuleID : 27062 - Revision : 2 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer 8 deleted object access via timer memory corrupti...
RuleID : 27061 - Revision : 3 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer CDispNode float css element use after free attempt
RuleID : 26754 - Revision : 2 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer CDispNode float css element use after free attempt
RuleID : 26753 - Revision : 3 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer runtimeStyle memory corruption attempt
RuleID : 26642 - Revision : 3 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer runtimeStyle memory corruption attempt
RuleID : 26641 - Revision : 4 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer VML array with negative length memory corruption ...
RuleID : 26638 - Revision : 6 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer DCOMTextNode object use after free attempt
RuleID : 26637 - Revision : 6 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer DCOMTextNode object use after free attempt
RuleID : 26636 - Revision : 6 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer 8 deleted object access via timer memory corrupti...
RuleID : 26635 - Revision : 4 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer 8 deleted object access via timer memory corrupti...
RuleID : 26634 - Revision : 5 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer html reload loop attempt
RuleID : 26633 - Revision : 7 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer CDispNode float css element use after free attempt
RuleID : 26631 - Revision : 2 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer CDispNode float css element use after free attempt
RuleID : 26630 - Revision : 3 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer setInterval focus use after free attempt
RuleID : 26629 - Revision : 3 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer 7-9 VBScript JSON reference information disclosur...
RuleID : 26625 - Revision : 3 - Type : BROWSER-IE
2014-01-10Microsoft Internet Explorer 7-9 VBScript JSON reference information disclosur...
RuleID : 26624 - Revision : 4 - Type : BROWSER-IE

Nessus® Vulnerability Scanner

DateDescription
2013-05-15Name : The remote host is affected by multiple code execution vulnerabilities.
File : smb_nt_ms13-037.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

SourceUrl
CERT http://www.us-cert.gov/ncas/alerts/TA13-134A
EXPLOIT-DB https://www.exploit-db.com/exploits/40894/
MISC http://blog.skylined.nl/20161208001.html
http://packetstormsecurity.com/files/140092/Microsoft-Internet-Explorer-9-MSH...
MS https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13...

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
DateInformations
2018-10-13 05:18:38
  • Multiple Updates
2017-09-19 09:25:52
  • Multiple Updates
2016-12-31 09:24:17
  • Multiple Updates
2016-09-30 00:23:51
  • Multiple Updates
2014-02-17 11:17:23
  • Multiple Updates
2014-01-19 21:29:13
  • Multiple Updates
2013-12-31 13:19:08
  • Multiple Updates
2013-11-04 21:26:01
  • Multiple Updates
2013-05-16 17:03:08
  • Multiple Updates
2013-05-15 13:18:42
  • First insertion