9.3
CVE-2013-0030
- EPSS 26.7%
- Veröffentlicht 13.02.2013 12:04:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka "VML Memory Corruption Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Internet Explorer Version 9
Microsoft ≫ Windows 7 Edition x64
Microsoft ≫ Windows 7 Edition x86
Microsoft ≫ Windows 7 Update sp1 Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows 7 Edition x86
Microsoft ≫ Windows 7 Update sp1 Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Internet Explorer Version 8
Microsoft ≫ Windows 7 Version -
Microsoft ≫ Windows 7 Version - Update sp1 Edition x64
Microsoft ≫ Windows 7 Version - Update sp1 Edition x86
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update r2 Edition itanium
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Windows 7 Version - Update sp1 Edition x64
Microsoft ≫ Windows 7 Version - Update sp1 Edition x86
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update r2 Edition itanium
Microsoft ≫ Windows Server 2008 Update r2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Microsoft ≫ Internet Explorer Version 10
Microsoft ≫ Windows 8 Version - Update - Edition x64
Microsoft ≫ Windows 8 Version - Update - Edition x86
Microsoft ≫ Windows Rt Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows 8 Version - Update - Edition x86
Microsoft ≫ Windows Rt Version -
Microsoft ≫ Windows Server 2012 Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 26.7% | 0.978 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://www.us-cert.gov/cas/techalerts/TA13-043B.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-010
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16175