[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-3131Date: (C)2013-07-26   (M)2024-04-08


Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
MS13-052
TA13-190A
oval:org.mitre.oval:def:17032
oval:org.mitre.oval:def:17261

CPE    11
cpe:/a:microsoft:.net_framework:3.5
cpe:/a:microsoft:.net_framework:4.5
cpe:/a:microsoft:silverlight:5.0.60818.0
cpe:/a:microsoft:silverlight:5.1.10411.0
...
CWE    1
CWE-94
OVAL    4
oval:org.secpod.oval:def:14320
oval:org.secpod.oval:def:14318
oval:org.secpod.oval:def:14328
oval:org.secpod.oval:def:14322
...

© SecPod Technologies