← All CVEs

CVE-2014-1806

high · 10

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."

10
CVSS
39.6%
EPSS (exploit prob.)
99th
EPSS percentile
2014-05-14
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
microsoft.net_framework1.1
microsoft.net_framework2.0
microsoft.net_framework3.5
microsoft.net_framework3.5.1
microsoft.net_framework4.0
microsoft.net_framework4.5
microsoft.net_framework4.5.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-1806