CVE-2013-0090

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka Internet Explorer CCaret Use After Free Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
18.796

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2809289)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2809289) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2809289) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2809289) for SP1Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2809289) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2809289)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2809289)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2809289) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2809289) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2809289) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2809289)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2809289)Windows
Cumulative Security Update for Internet Explorer for Windows XP (KB2809289)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13262Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2809289)
PATCH-13264Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2809289)
PATCH-13265Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2809289)
PATCH-13266Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2809289)
PATCH-13267Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2809289)
PATCH-13268Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2809289)
PATCH-13269Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2809289)
PATCH-13270Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2809289)
PATCH-13271Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2809289)
PATCH-13272Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2809289)
PATCH-13273Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2809289)
PATCH-13274Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2809289)
PATCH-13275Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2809289)
PATCH-13276Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2809289)
PATCH-13277Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2809289)
PATCH-13278Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2809289)
PATCH-13279Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2809289)
PATCH-13280Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2809289)
PATCH-13281Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2809289)
PATCH-13282Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2809289)
PATCH-13283Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2809289)
PATCH-13284Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2809289)
PATCH-13285Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2809289)
PATCH-13286Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2809289)
PATCH-13287Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2809289)
PATCH-13288Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2809289)
PATCH-13289Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2809289)
PATCH-13290Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2809289)
PATCH-13291Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2809289)
PATCH-13292Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2809289)
PATCH-13293Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2809289)
PATCH-13294Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2809289)
PATCH-13295Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2809289)
PATCH-13297Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2809289)
PATCH-13298Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2809289)
PATCH-13299Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2809289)
PATCH-13301Cumulative Security Update for Internet Explorer for Windows XP (KB2809289)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234