CVE-2013-0030

Description

The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka VML Memory Corruption Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
34.996

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Internet Explorer 6 for Windows XP (KB2797052)Windows
Security Update for Internet Explorer 6 for Windows Server 2003 (KB2797052)Windows
Security Update for Internet Explorer 6 for Windows Server 2003 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows XP (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows Vista (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows Server 2008 (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows Vista for x64-based Systems (KB2797052)Windows
Security Update for Internet Explorer 7 for Windows Server 2008 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows XP (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows Vista (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows Server 2008 (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows 7 (KB2797052) x86 based systemsWindows
Security Update for Internet Explorer 8 for Windows 7 (KB2797052) x86 based systems for SP1Windows
Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows Vista for x64-based Systems (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows Server 2008 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2797052) for SP1Windows
Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2797052) for SP1Windows
Security Update for Internet Explorer 9 for Windows Vista (KB2797052)Windows
Security Update for Internet Explorer 9 for Windows Server 2008 (KB2797052)Windows
Security Update for Internet Explorer 9 for Windows 7 (KB2797052) x86 based systemsWindows
Security Update for Internet Explorer 9 for Windows 7 (KB2797052) x86 based systems for SP1Windows
Security Update for Internet Explorer 9 for Windows Vista for x64-based Systems (KB2797052)Windows
Security Update for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 9 for Windows 7 for x64-based Systems (KB2797052)Windows
Security Update for Internet Explorer 9 for Windows 7 for x64-based Systems (KB2797052) for SP1Windows
Security Update for Internet Explorer 9 for Windows Server 2008 R2 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 9 for Windows Server 2008 R2 x64 Edition (KB2797052)Windows
Security Update for Internet Explorer 10 for Windows 8 (KB2797052)Windows
Security Update for Internet Explorer 10 for Windows 8 for x64-based Systems (KB2797052)Windows
Security Update for Internet Explorer 10 for Windows Server 2012 x64 Edition (KB2797052)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13101Security Update for Internet Explorer 6 for Windows XP (KB2797052)
PATCH-13102Security Update for Internet Explorer 6 for Windows Server 2003 (KB2797052)
PATCH-13104Security Update for Internet Explorer 6 for Windows Server 2003 x64 Edition (KB2797052)
PATCH-13105Security Update for Internet Explorer 7 for Windows XP (KB2797052)
PATCH-13106Security Update for Internet Explorer 7 for Windows Server 2003 (KB2797052)
PATCH-13107Security Update for Internet Explorer 7 for Windows Vista (KB2797052)
PATCH-13108Security Update for Internet Explorer 7 for Windows Server 2008 (KB2797052)
PATCH-13109Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2797052)
PATCH-13110Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2797052)
PATCH-13111Security Update for Internet Explorer 7 for Windows Vista for x64-based Systems (KB2797052)
PATCH-13112Security Update for Internet Explorer 7 for Windows Server 2008 x64 Edition (KB2797052)
PATCH-13113Security Update for Internet Explorer 8 for Windows XP (KB2797052)
PATCH-13114Security Update for Internet Explorer 8 for Windows Server 2003 (KB2797052)
PATCH-13115Security Update for Internet Explorer 8 for Windows Vista (KB2797052)
PATCH-13116Security Update for Internet Explorer 8 for Windows Server 2008 (KB2797052)
PATCH-13117Security Update for Internet Explorer 8 for Windows 7 (KB2797052)
PATCH-13118Security Update for Internet Explorer 8 for Windows 7 (KB2797052)
PATCH-13119Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2797052)
PATCH-13120Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2797052)
PATCH-13121Security Update for Internet Explorer 8 for Windows Vista for x64-based Systems (KB2797052)
PATCH-13122Security Update for Internet Explorer 8 for Windows Server 2008 x64 Edition (KB2797052)
PATCH-13123Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2797052)
PATCH-13124Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2797052)
PATCH-13125Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2797052)
PATCH-13126Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2797052)
PATCH-13127Security Update for Internet Explorer 9 for Windows Vista (KB2797052)
PATCH-13129Security Update for Internet Explorer 9 for Windows 7 (KB2797052)
PATCH-13130Security Update for Internet Explorer 9 for Windows 7 (KB2797052)
PATCH-13131Security Update for Internet Explorer 9 for Windows Vista for x64-based Systems (KB2797052)
PATCH-13132Security Update for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB2797052)
PATCH-13133Security Update for Internet Explorer 9 for Windows 7 for x64-based Systems (KB2797052)
PATCH-13134Security Update for Internet Explorer 9 for Windows 7 for x64-based Systems (KB2797052)
PATCH-13135Security Update for Internet Explorer 9 for Windows Server 2008 R2 x64 Edition (KB2797052)
PATCH-13137Security Update for Internet Explorer 10 for Windows 8 (KB2797052)
PATCH-13138Security Update for Internet Explorer 10 for Windows 8 for x64-based Systems (KB2797052)
PATCH-13139Security Update for Internet Explorer 10 for Windows Server 2012 x64 Edition (KB2797052)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234