CVE-2016-3255
high · 7.5Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
7.5
CVSS
24.7%
EPSS (exploit prob.)
98th
EPSS percentile
2016-07-13
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | .net_framework | 2.0 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 3.5.1 |
| microsoft | .net_framework | 4.5.2 |
| microsoft | .net_framework | 4.6 |
| microsoft | .net_framework | 4.6.1 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/91601
- http://www.securitytracker.com/id/1036291
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-091
- http://www.securityfocus.com/bid/91601
- http://www.securitytracker.com/id/1036291
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-091
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-3255