Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2013-3917 | First vendor Publication | 2013-11-12 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3915. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3917 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:19138 | |||
Oval ID: | oval:org.mitre.oval:def:19138 | ||
Title: | Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2013-3917) - MS13-088 | ||
Description: | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3915. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2013-3917 | Version: | 5 |
Platform(s): | Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 Microsoft Windows XP Microsoft Windows Vista | Product(s): | Microsoft Internet Explorer 6 Microsoft Internet Explorer 7 Microsoft Internet Explorer 8 Microsoft Internet Explorer 9 Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2013-11-14 | IAVM : 2013-A-0215 - Cumulative Security Update for Microsoft Internet Explorer Severity : Category I - VMSKEY : V0042296 |
Snort® IPS/IDS
Date | Description |
---|---|
2015-02-18 | Microsoft Internet Explorer CAnchorElement use after free attempt RuleID : 33099 - Revision : 5 - Type : BROWSER-IE |
2014-01-18 | Microsoft Internet Explorer print preview information disclosure attempt RuleID : 28997 - Revision : 2 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer generic use after free attempt RuleID : 28524 - Revision : 2 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer generic use after free attempt RuleID : 28523 - Revision : 2 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer print preview information disclosure attempt RuleID : 28522 - Revision : 4 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer undo use after free attempt RuleID : 28504 - Revision : 2 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer createRange user after free attempt RuleID : 28496 - Revision : 4 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer execCommand CTreePos memory corruption attempt RuleID : 28495 - Revision : 3 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer execCommand CTreePos memory corruption attempt RuleID : 28494 - Revision : 3 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer freed CTreePos object use-after-free attempt RuleID : 28492 - Revision : 3 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer CEditAdorner use after free attempt RuleID : 28491 - Revision : 2 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer deleted object memory corruption attempt RuleID : 28490 - Revision : 3 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer CAnchorElement use after free attempt RuleID : 28489 - Revision : 6 - Type : BROWSER-IE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-11-13 | Name : The remote host is affected by multiple code execution vulnerabilities. File : smb_nt_ms13-088.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:36:04 |
|
2021-05-04 12:27:04 |
|
2021-04-22 01:32:45 |
|
2020-05-23 00:37:50 |
|
2018-10-13 05:18:42 |
|
2017-09-19 09:26:14 |
|
2014-02-17 11:21:35 |
|
2014-01-19 21:29:34 |
|
2013-12-20 13:19:36 |
|
2013-12-05 17:20:44 |
|
2013-11-15 21:20:58 |
|
2013-11-13 21:21:40 |
|
2013-11-13 13:19:15 |
|