[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-1671Date: (C)2015-05-15   (M)2024-04-10


The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1032281
BID-74490
MS15-044

CPE    10
cpe:/a:microsoft:.net_framework:3.5
cpe:/a:microsoft:.net_framework:4.5
cpe:/a:microsoft:.net_framework:3.5.1
cpe:/a:microsoft:office:2007:sp3
...
CWE    1
CWE-19
OVAL    4
oval:org.secpod.oval:def:24341
oval:org.secpod.oval:def:24342
oval:org.secpod.oval:def:24338
oval:org.secpod.oval:def:24340
...

© SecPod Technologies