CVE-2015-1715
published 2015-05-13CVE-2015-1715: Microsoft Silverlight 5 before 5.1.40416.00 allows remote attackers to bypass intended integrity-level restrictions via a crafted Silverlight application, aka…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
13.34%
96.0th percentile
Microsoft Silverlight 5 before 5.1.40416.00 allows remote attackers to bypass intended integrity-level restrictions via a crafted Silverlight application, aka "Microsoft Silverlight Out of Browser Application Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | silverlight | <= 5.1.30214.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - May 2015
blogs_talos·2015-05-12·CVSS 4.3
[MEDIUM] Microsoft Patch Tuesday - May 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 13 bulletins being released which address 48 CVEs. Three of the bulletins are listed as Critical and address vulnerabilities in Internet Explorer, GDI+ Font Parsing, and Windows Journal. The remaining ten bulletins are marked as Important and address vulnerabilities in Microsoft Office, Sharepoint, .NET, Silverlight, Service Control Manager, Windows Kernel, VBScript/JScript, Microsoft Management Console, and Secure Channel.
## Bulletins Rated CriticalMS15-043, MS15-044, and MS15-045 are rated Critical.
MS15-043 is this month’s Internet Explorer security bulletin with vulnerabilities in versions 6 through 11 being ad
Talos
Microsoft Patch Tuesday - May 2015
blogs_talos·2015-05-12·CVSS 4.3
[MEDIUM] Microsoft Patch Tuesday - May 2015
## Microsoft Patch Tuesday - May 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 13 bulletins being released which address 48 CVEs. Three of the bulletins are listed as Critical and address vulnerabilities in Internet Explorer, GDI+ Font Parsing, and Windows Journal. The remaining ten bulletins are marked as Important and address vulnerabilities in Microsoft Office, Sharepoint, .NET, Silverlight, Service Control Manager, Windows Kernel, VBScript/JScript, Microsoft Management Console, and Secure Channel.
## Bulletins Rated Critical MS15-043, MS15-044, and MS15-045 are rated Critical.
MS15-043 is this month’s Internet Explorer security bulletin with vulnerabi
Bugzilla
CVE-2015-3247 spice: memory corruption in worker_update_monitors_config()
bugzilla·2015-06-18·CVSS 6.9
CVE-2015-3247 [MEDIUM] CVE-2015-3247 spice: memory corruption in worker_update_monitors_config()
CVE-2015-3247 spice: memory corruption in worker_update_monitors_config()
It was reported that function worker_update_monitors_config in spice-server contains a race condition which can be exploited as a heap corruption from the guest.
Suggested patch: https://bugzilla.redhat.com/attachment.cgi?id=1037193
Acknowledgements:
This issue was discovered by Frediano Ziglio of Red Hat.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:1715 https://rhn.redhat.com/errata/RHSA-2015-1715.html
---
This issue has been addressed in the following products:
RHEV-H and Agents for RHEL-6
RHEV-H and Agents for RHEL-7
Via RHSA-2015:1713 https://rhn.redhat.com/errata/RHSA-2015-1713.html
---
This issue has been addressed in the following
2015-05-13
Published