Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-3860
HistoryOct 09, 2013 - 2:53 p.m.

Design/Logic Flaw

2013-10-0914:53:00
PRIOn knowledge base
www.prio-n.com
2

7 High

AI Score

Confidence

High

0.271 Low

EPSS

Percentile

96.8%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML document, aka “Entity Expansion Vulnerability.”

7 High

AI Score

Confidence

High

0.271 Low

EPSS

Percentile

96.8%