CVE-2015-2504

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array copy, which allows remote attackers to (1) execute arbitrary code via a crafted XAML browser application (XBAP) or (2) bypass Code Access Security restrictions via a crafted .NET Framework application, aka ".NET Elevation of Privilege Vulnerability."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*

History

21 Nov 2024, 02:27

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/76560 - () http://www.securityfocus.com/bid/76560 -
References () http://www.securitytracker.com/id/1033493 - () http://www.securitytracker.com/id/1033493 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-101 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-101 -

Information

Published : 2015-09-09 00:59

Updated : 2024-11-21 02:27


NVD link : CVE-2015-2504

Mitre link : CVE-2015-2504

CVE.ORG link : CVE-2015-2504


JSON object : View

Products Affected

microsoft

  • .net_framework
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer