CVE-2015-2504
high · 9.3Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array copy, which allows remote attackers to (1) execute arbitrary code via a crafted XAML browser application (XBAP) or (2) bypass Code Access Security restrictions via a crafted .NET Framework application, aka ".NET Elevation of Privilege Vulnerability."
9.3
CVSS
21.0%
EPSS (exploit prob.)
97th
EPSS percentile
2015-09-09
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | .net_framework | 2.0 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 3.5.1 |
| microsoft | .net_framework | 4.0 |
| microsoft | .net_framework | 4.5 |
| microsoft | .net_framework | 4.5.1 |
| microsoft | .net_framework | 4.5.2 |
| microsoft | .net_framework | 4.6 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/76560
- http://www.securitytracker.com/id/1033493
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-101
- http://www.securityfocus.com/bid/76560
- http://www.securitytracker.com/id/1033493
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-101
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-2504