Lucene search

K
cve[email protected]CVE-2013-3131
HistoryJul 10, 2013 - 3:46 a.m.

CVE-2013-3131

2013-07-1003:46:09
CWE-94
web.nvd.nist.gov
31
microsoft
.net framework
silverlight
remote code execution
vulnerability
nvd
cve-2013-3131

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.825 High

EPSS

Percentile

98.4%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka “Array Access Violation Vulnerability.”

Affected configurations

NVD
Node
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5
OR
microsoft.net_frameworkMatch3.5.1
OR
microsoft.net_frameworkMatch4.0
OR
microsoft.net_frameworkMatch4.5
OR
microsoftsilverlightMatch5.0.60401.0
OR
microsoftsilverlightMatch5.0.60818.0
OR
microsoftsilverlightMatch5.0.60818.0rc
OR
microsoftsilverlightMatch5.0.61118.0
OR
microsoftsilverlightMatch5.1.10411.0
OR
microsoftsilverlightMatch5.1.20125.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.825 High

EPSS

Percentile

98.4%