Skip to main content

CVE detail

CVE-2013-2551

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.

CVSS 8.8 · HighBuzz score 66.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 66.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
21 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
21 source links · newest first
  • RIG exploit kit distributes Princess ransomwareMalwarebytes Labs

    We have identified a new drive-by download campaign that distributes the Princess ransomware (AKA PrincessLocker), leveraging compromised websites and the RIG…

    newswww.malwarebytes.comAug 30, 2017, 5:00 PM
  • A new exploit kit (EK) has emerged recently on underground forums, where a malware developer is advertising it starting at just $80.

    newswww.securityweek.comAug 15, 2017, 12:46 PM
  • The Disdain exploit kit is available for rent on a daily, weekly, or monthly basis for prices of $80, $500, and $1,400 respectively. The security researcher David Montenegro discovered a new exploit kit dubbed Disdain that is offered for rent on underground hacking forums by a malware developer using the pseudonym of Cehceny. https://twitter.com/CryptoInsane/status/895151680861253632 The Disdain exploit […]

    newssecurityaffairs.comAug 15, 2017, 7:48 AM
  • Exploit kits: Winter 2017 reviewMalwarebytes Labs

    A few months have passed since our Fall 2016 review of the most common exploit kits we are seeing in our telemetry and honeypots. Today, we take another look at the current (bleak) EK scene by going over RIG, Sundown, Neutrino and Magnitude. There haven’t been any major changes in the past little while and exploit kit-related infections remain low compared to those via malicious spam. This is in part due to the lack of fresh and reliable exploits in today’s drive-by landscape. Pseudo-Darkleech and EITest are the most popular redirection campaigns from compromised websites. They refer to code that is injected into – for the most part – WordPress , Joomla , or Drupal websites and automatically redirects visitors to an exploit kit landing page. Malvertising campaigns keep fuelling redirections to exploit kits as well, but can greatly vary in size and impact. The daily malverts from shady ad networks continue unchanged while the larger attacks going after top ad networks and publishers co…

    newswww.malwarebytes.comMar 8, 2017, 5:00 PM
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • Exploit kits: Fall 2016 reviewMalwarebytes Labs

    There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…

    newswww.malwarebytes.comNov 8, 2016, 5:00 PM
  • The developers of the RIG exploit kit appear to be testing new infection methods and a different type of URL pattern for command and control (C&C) communications that could help the threat evade detection.

    newswww.securityweek.comSep 1, 2016, 10:26 AM
  • LAS VEGAS – Earlier this year, a disgruntled reseller leaked the source code for version 2.0 of the RIG exploit kit. Since then, the RIG’s author has released version 3.0, which was recently discovered by researchers from Trustwave. The latest version uses malvertising in order to deliver a majority of its traffic, infecting some 1.25 […]

    newswww.csoonline.comAug 3, 2015, 4:00 PM
  • Security researcher discovered a strain of the Kovter trojan that has been updating Flash Player and Internet Explorer to prevent further infections. The French security expert Kafeine have discovered a new strain of the Kovter malware noticing that the instance of the malicious code he was analyzing was attempting to download the latest version of the Flash […]

    newssecurityaffairs.comJul 4, 2015, 5:13 AM
  • The ad fraud Trojan known as Kovter has been updating Adobe Flash Player and Microsoft Internet Explorer on infected systems, most likely in an effort to keep other malware out. The French security researcher known as Kafeine discovered this new Kovter trick when he noticed that some of his virtual machines were attempting to download the latest version of Flash Player.

    newswww.securityweek.comJul 3, 2015, 11:47 AM
  • Over a hundred forum websites have been compromised and injected with code that redirects users to sites hosting the Fiesta exploit kit, Cyphort researchers have found. These are not highly popular forums, but gather a respectable number of users who like to discuss DIY projects, animals, wrestling, scuba diving, news regarding PS3, and so on. They are powered by either vBulletin or by IP Board online forum software, new vulnerabilities for which are often found … More →

    newswww.helpnetsecurity.comApr 10, 2015, 12:12 AM
  • New crypto-ransomware encrypts video games filesHelp Net Security

    A new piece of ransomware that (mis)uses the Cryptolocker “brand” has been analyzed by Bromium researchers, and they discovered that aside from the usual assortment of file types that ransomware usually targets, this variant also encrypts file types associated with video games and game related software. But not all video games, and not the most popular ones. It targets files associated with single users games Call of Duty, Star Craft 2, Diablo, Fallout 3, Minecraft, … More →

    newswww.helpnetsecurity.comMar 12, 2015, 9:42 AM
  • Security experts at Trend Micro detected a new banking trojan dubbed TSPY_BANKER.YYSI which uses Pinterest as command and control system. According to researchers at Trend Micro once again, banks in South Korea are targeted by a new financial malware designed to target their customers. The attackers have targeted customers of the principal financial institutions of […]

    newssecurityaffairs.comDec 16, 2014, 3:57 PM
  • A new financial malware designed to target the customers of South Korean banks has been spotted in the wild by researchers at Trend Micro.

    newswww.securityweek.comDec 16, 2014, 2:18 PM
  • Earlier this morning, CSO published new information on the Magnitude Exploit Kit, a criminal project known for its ties to attacks on Yahoo and PHP.net, as well as several other websites. The story was made possible thanks to help from researchers at Trustwave. Today’s update will examine some highlights from that research, with commentary from […]

    newswww.csoonline.comAug 5, 2014, 12:33 PM
  • LAS VEGAS (Black Hat USA) – Researchers at Trustwave have provided CSO with an inside look at the Magnitude Exploit Kit’s infrastructure. Linked to attacks against PHP.net and Yahoo, this kit has gone from obscurity to a certified threat in a short amount of time, while generating more than $60,000 USD per week in income. […]

    newswww.csoonline.comAug 5, 2014, 10:00 AM
  • Facebook has removed a scam that was redirecting users to the Nuclear exploit kit, according to researchers with Symantec. The scam relied on users getting drawn into clicking on a link promoting a work-from-home opportunity with the headline: ‘EXPOSED: Mom Makes $8,000/Month and You Won’t Believe How She Does It!’

    newswww.securityweek.comJul 23, 2014, 11:47 PM
  • Researchers at Symantec recently discovered that poplar video-sharing site Dailymotion was redirecting users to the Sweet Orange exploit kit. For its victims, the Sweet Orange kit may be sour to taste. The kit exploits vulnerabilities in Internet Explorer, Java and Adobe Flash Player. The researchers discovered the infection June 28. The site was cleaned last week, and is no longer infected.

    newswww.securityweek.comJul 7, 2014, 4:55 PM
  • Hours after Google’s Safe Browsing initiative flagged the website for malware, PHP.net confirmed that two of their servers were compromised and used to attack visitors. However, the administrators are still not sure how the attackers accessed the servers. [PHP.net flagged for malware by Google, researchers confirm it was no false positive] The admission follows a […]

    newswww.csoonline.comOct 25, 2013, 3:00 PM
  • Two distinct spam campaigns taking advantage of the current political situation in Syria have been spotted by Symantec and Kaspersky Lab researchers. The first one consists of an email simply stating “Dear sir, please find the attachment”, urging the user to open the chemical attack in Syria.doc file in the attachment. The file contains a recent Washington Post article, but is also specially crafted to exploit a Microsoft Internet Explorer vulnerability (CVE-2013-2551) and, if successful, … More →

    newswww.helpnetsecurity.comSep 9, 2013, 8:30 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence