CVE-2013-0030: Buffer Overflow
Published Feb 13, 2013
·Updated
The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka "VML Memory Corruption Vulnerability."
Affected Software
67 affected components
All of the following
Microsoft Internet Explorer=6
Any of the following
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
All of the following
Microsoft Internet Explorer=7
Any of the following
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
All of the following
Microsoft Internet Explorer=9
Any of the following
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
All of the following
Microsoft Internet Explorer=8
Any of the following
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
All of the following
Microsoft Internet Explorer=10
Any of the following
Microsoft Windows 8
Microsoft Windows 8
Microsoft Windows RT
Microsoft Windows Server 2012
Microsoft Internet Explorer=6
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Microsoft Internet Explorer=7
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Internet Explorer=9
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Vista=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Internet Explorer=10
Microsoft Windows 8
Microsoft Windows 8
Microsoft Windows RT
Microsoft Windows Server 2012
Event History
Feb 13, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0030?
CVE-2013-0030 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2013-0030?
To fix CVE-2013-0030, users should update Microsoft Internet Explorer to a patched version provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2013-0030?
CVE-2013-0030 affects Internet Explorer versions 6 through 10.
4
What types of attacks can CVE-2013-0030 enable?
CVE-2013-0030 can enable remote code execution attacks via specially crafted web pages.
5
Are any Windows versions not vulnerable to CVE-2013-0030?
Microsoft Windows versions that are not running affected Internet Explorer versions are not vulnerable to CVE-2013-0030.