CVE-2015-2526Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft NET Framework

Severity
5.0MEDIUMNVD
EPSS
18.4%
top 4.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 9
Latest updateMay 14

Description

Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC Denial of Service Vulnerability."

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmicrosoft/net_framework4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-pc33-hpmh-68rj: Microsoft2022-05-14
CVEList
CVE-2015-2526: Microsoft2015-09-09

📋Vendor Advisories

34
Red Hat
chromium-browser: Use-After-free in MidiHost2015-12-23
Red Hat
chromium-browser: Fixes from internal audits and fuzzing2015-12-15
Red Hat
v8: multiple vulnerabilities fixed in 4.7.80.232015-12-14
Red Hat
chromium-browser: Use-after free in Blink2015-12-08
Red Hat
chromium-browser: Escaping issue in saved pages2015-12-08

💬Community

4
Bugzilla
CVE-2015-8664 chromium-browser: Use-After-free in MidiHost2015-12-30
Bugzilla
CVE-2015-6792 chromium-browser: Fixes from internal audits and fuzzing2015-12-16
Bugzilla
CVE-2015-8548 v8: multiple vulnerabilities fixed in 4.7.80.232015-12-14
Bugzilla
CVE-2015-8478 v8: multiple vulnerabilities fixed in 4.7.80.232015-12-08
CVE-2015-2526 — Microsoft NET Framework vulnerability | cvebase