CVE detail
CVE-2013-1288
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CTreeNode Use After Free Vulnerability."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
0 0 1 758 4323 Wired Business Media 36 10 5071 14.0 Normal 0
newswww.securityweek.comMar 12, 2013, 6:23 PM- Microsoft releases four critical bulletinsHelp Net Security
In terms of volume, the March Patch Tuesday is about average, with seven bulletins — four rated “critical” and three rated “important.” In technical terms though we are seeing some interesting vulnerabilities that definitely rate higher-than-average. Our lineup starts with MS13-021, a patch for Internet Explorer that addresses nine distinct vulnerabilities. One of the vulnerabilities (CVE-2013-1288) had an exploit out in the wild for one month, but almost nobody noticed it. It appears that while … More →
newswww.helpnetsecurity.comMar 12, 2013, 2:05 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2013-0094CVSS 9.3 · Critical
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted…
- CVE-2013-0093CVSS 9.3 · Critical
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted…
- CVE-2013-0092CVSS 9.3 · Critical
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted…
- CVE-2013-0091CVSS 9.3 · Critical
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, ak…
- CVE-2013-0090CVSS 8.8 · High
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted…
- CVE-2013-0089CVSS 9.3 · Critical
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted…