Lucene search

K
cveMicrosoftCVE-2012-0015
HistoryFeb 14, 2012 - 10:55 p.m.

CVE-2012-0015

2012-02-1422:55:01
CWE-94
microsoft
web.nvd.nist.gov
39
cve-2012-0015
microsoft
.net framework
buffer overflow
remote code execution
security vulnerability
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.286

Percentile

96.9%

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka “.NET Framework Heap Corruption Vulnerability.”

Affected configurations

Nvd
Node
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5.1
AND
microsoftwindows_7x64
OR
microsoftwindows_7x86
OR
microsoftwindows_7sp1x64
OR
microsoftwindows_7sp1x86
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_server_2008sp2x86
OR
microsoftwindows_server_2008Matchr2itanium
OR
microsoftwindows_server_2008Matchr2x64
OR
microsoftwindows_vistasp2
OR
microsoftwindows_xpsp3
VendorProductVersionCPE
microsoft.net_framework2.0cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
microsoft.net_framework3.5.1cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
microsoftwindows_7*cpe:2.3:o:microsoft:windows_7:*:*:x64:*:*:*:*:*
microsoftwindows_7*cpe:2.3:o:microsoft:windows_7:*:*:x86:*:*:*:*:*
microsoftwindows_7*cpe:2.3:o:microsoft:windows_7:*:sp1:x64:*:*:*:*:*
microsoftwindows_7*cpe:2.3:o:microsoft:windows_7:*:sp1:x86:*:*:*:*:*
microsoftwindows_server_2003*cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
microsoftwindows_server_2008*cpe:2.3:o:microsoft:windows_server_2008:*:sp2:x64:*:*:*:*:*
microsoftwindows_server_2008*cpe:2.3:o:microsoft:windows_server_2008:*:sp2:x86:*:*:*:*:*
microsoftwindows_server_2008r2cpe:2.3:o:microsoft:windows_server_2008:r2:*:itanium:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.286

Percentile

96.9%