CVE-2013-0002
published 2013-01-09CVE-2013-0002: Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows…
PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
25.12%
97.7th percentile
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_apache7.5CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c9mm-w4jh-r45h: Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft
ghsa_unreviewed·2022-05-05
CVE-2013-0002 [HIGH] CWE-119 GHSA-c9mm-w4jh-r45h: Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
Kernel
HID: sony: validate HID output report details
kernel_security·2013-09-11·CVSS 4.7
CVE-2013-2890 [MEDIUM] HID: sony: validate HID output report details
HID: sony: validate HID output report details
This driver must validate the availability of the HID output report and
its size before it can write LED states via buzz_set_leds(). This stops
a heap overflow that is possible if a device provides a malicious HID
output report:
[ 108.171280] usb 1-1: New USB device found, idVendor=054c, idProduct=0002
...
[ 117.507877] BUG kmalloc-192 (Not tainted): Redzone overwritten
CVE-2013-2890
Signed-off-by: Kees Cook
Cc: [email protected] #3.11
Reviewed-by: Benjamin Tissoires
Signed-off-by: Jiri Kosina
Apache
Apache camel: CVE-2014-0002
vendor_apache·CVSS 7.5
CVE-2014-0002 [CRITICAL] Apache camel: CVE-2014-0002
Apache camel: CVE-2014-0002
2.11.0 up to 2.11.3, 2.12.0 up to 2.12.2 2.11.4, 2.12.3, 2.13.0 and newer CRITICAL The Apache Camel XSLT component will resolve entities in XML messages when transforming them using an xslt route. 2013
Severity: critical
No detection rules found.
No public exploits indexed.
http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-004https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16343http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-004https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16343
2013-01-09
Published