CVE-2013-0086Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Sharepoint Foundation

Severity
5.0MEDIUMNVD
EPSS
34.2%
top 3.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 5

Description

Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-wq8h-rhq6-9hxx: Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive inform2022-05-05
CVEList
CVE-2013-0086: Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive inform2013-03-13

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 03-12-2013
CVE-2013-0086 — Microsoft vulnerability | cvebase