CVE detail
CVE-2013-1347
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- The evolutions of APT28 attacksSecurity Affairs
Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]
newssecurityaffairs.comDec 5, 2019, 6:41 AM - Why do we need for Incident Response plan?Security Affairs
Due to the constant growth in the number of cyber attacks it is necessary to properly define the actions composing an incident response plan. FireEye firm published an interesting post on the need of incident response (IR) capabilities to reply numerous cyber attacks that daily hit almost any web service. Starting from the data proposed […]
newssecurityaffairs.comNov 26, 2013, 7:58 PM Attackers are increasingly dodging the address space layout randomization [ASLR] mechanisms used to thwart buffer overflow attacks.
newswww.securityweek.comOct 15, 2013, 9:34 PMWhile application sandboxes can isolate threats and protect endpoints from certain types of malware attacks, there are fundamental issues in how they are designed, according to new research from Bromium.
newswww.securityweek.comJul 24, 2013, 4:03 PM- Microsoft fixes 33 vulnerabilitiesHelp Net Security
Today for Patch Tuesday, Microsoft and Adobe are both coming out with critical fixes for a number of widely installed and attacked programs. Microsoft has 10 bulletins addressing a total of 33 vulnerabilities, and Adobe is releasing new versions of Adobe Reader, Adobe Flash and Coldfusion. Two of the Microsoft bulletins, MS13-038 and MS13-037, are fixes for vulnerabilities in Internet Explorer (IE). They are both rated “critical” and should be implemented first in this month’s … More →
newswww.helpnetsecurity.comMay 14, 2013, 2:08 PM - Microsoft Releases ‘Fix It’ to Address Recent IE Vulnerability Used in Watering Hole AttacksSecurityWeek
Microsoft on Wednesday released a one-click Fix it to help protect customers from a recently-disclosed security vulnerability ( CVE-2013-1347 ) affecting Internet Explorer 8 that was used in recent watering hole attacks that hit several sites including the website for the U.S. Department of Labor.
newswww.securityweek.comMay 8, 2013, 10:05 PM Microsoft has released a temporary fix for a zero-day vulnerability in Internet Explorer 8, which was used by hackers in a prominent attack against the U.S. Department of Labor’s website. The problem is particularly dangerous since it can allow an attacker to install malware merely by visiting a tampered web page. Microsoft is still working […]
newswww.csoonline.comMay 8, 2013, 3:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2014-1776CVSS 9.8 · Critical
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vec…
- CVE-2013-3897CVSS 8.8 · High
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a de…
- CVE-2013-2551CVSS 8.8 · High
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted…
- CVE-2012-4792CVSS 8.8 · High
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object…
- CVE-2012-4969CVSS 8.1 · High
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a craft…
- CVE-2011-0346CVSS 8.1 · High
Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a…