Skip to main content

CVE detail

CVE-2013-1347

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.

CVSS 8.8 · HighBuzz score 55.3KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 55.3

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 20.8 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
20.8
7 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
7 source links · newest first
  • The evolutions of APT28 attacksSecurity Affairs

    Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]

    newssecurityaffairs.comDec 5, 2019, 6:41 AM
  • Why do we need for Incident Response plan?Security Affairs

    Due to the constant growth in the number of cyber attacks it is necessary to properly define the actions composing an incident response plan. FireEye firm published an interesting post on the need of incident response (IR) capabilities to reply numerous cyber attacks that daily hit almost any web service. Starting from the data proposed […]

    newssecurityaffairs.comNov 26, 2013, 7:58 PM
  • Attackers are increasingly dodging the address space layout randomization [ASLR] mechanisms used to thwart buffer overflow attacks.

    newswww.securityweek.comOct 15, 2013, 9:34 PM
  • While application sandboxes can isolate threats and protect endpoints from certain types of malware attacks, there are fundamental issues in how they are designed, according to new research from Bromium.

    newswww.securityweek.comJul 24, 2013, 4:03 PM
  • Microsoft fixes 33 vulnerabilitiesHelp Net Security

    Today for Patch Tuesday, Microsoft and Adobe are both coming out with critical fixes for a number of widely installed and attacked programs. Microsoft has 10 bulletins addressing a total of 33 vulnerabilities, and Adobe is releasing new versions of Adobe Reader, Adobe Flash and Coldfusion. Two of the Microsoft bulletins, MS13-038 and MS13-037, are fixes for vulnerabilities in Internet Explorer (IE). They are both rated “critical” and should be implemented first in this month’s … More →

    newswww.helpnetsecurity.comMay 14, 2013, 2:08 PM
  • Microsoft on Wednesday released a one-click Fix it to help protect customers from a recently-disclosed security vulnerability ( CVE-2013-1347 ) affecting Internet Explorer 8 that was used in recent watering hole attacks that hit several sites including the website for the U.S. Department of Labor.

    newswww.securityweek.comMay 8, 2013, 10:05 PM
  • Microsoft has released a temporary fix for a zero-day vulnerability in Internet Explorer 8, which was used by hackers in a prominent attack against the U.S. Department of Labor’s website. The problem is particularly dangerous since it can allow an attacker to install malware merely by visiting a tampered web page. Microsoft is still working […]

    newswww.csoonline.comMay 8, 2013, 3:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence