Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-2504

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array copy, which allows remote attackers to (1) execute arbitrary code via a crafted XAML browser application (XBAP) or (2) bypass Code Access Security restrictions via a crafted .NET Framework application, aka ".NET Elevation of Privilege Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.255
EPSS Ranking 95.9%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2015-2504


Contact Us

Shodan ® - All rights reserved