CVE-2013-0022
published 2013-02-13CVE-2013-0022: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to…
PriorityP356critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
EPSS
16.80%
96.7th percentile
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7qv4-9j3v-5hf5: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers a
ghsa_unreviewed·2022-05-05
CVE-2013-0022 [HIGH] CWE-416 GHSA-7qv4-9j3v-5hf5: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers a
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability."
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()
vendor_redhat·2011-04-13·CVSS 7.5
CVE-2013-4357 [HIGH] CWE-121 glibc: stack overflow in getaddrinfo()'s use of alloca()
glibc: stack overflow in getaddrinfo()'s use of alloca()
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
Statement: This issue has already been addressed in Red Hat Enterprise Linux 5 via http://rhn.redhat.com/errata/RHBA-2013-0022.html and in Red Hat Enterprise Linux 6 via http://rhn.redhat.com/errata/RHBA-2012-0763.html
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()
vendor_redhat·2011-04-13·CVSS 7.5
CVE-2012-6686 [HIGH] CWE-121 glibc: stack overflow in getaddrinfo()'s use of alloca()
glibc: stack overflow in getaddrinfo()'s use of alloca()
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2013-4357. Note: All CVE users should reference CVE-2013-4357 instead of this candidate.
Statement: This issue has already been addressed in Red Hat Enterprise Linux 5 via http://rhn.redhat.com/errata/RHBA-2013-0022.html and in Red Hat Enterprise Linux 6 via http://rhn.redhat.com/errata/RHBA-2012-0763.html
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
http://www.us-cert.gov/cas/techalerts/TA13-043B.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-009https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16069http://www.us-cert.gov/cas/techalerts/TA13-043B.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-009https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16069
2013-02-13
Published