Microsoft Silverlight vulnerabilities
32 known vulnerabilities affecting microsoft/silverlight.
Total CVEs
32
CISA KEV
4
actively exploited
Public exploits
9
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH12MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2012-0176P3CRITICALCVSS 9.3v4.0.50401.0v4.0.50524.00+10 more2012-05-09
CVE-2012-0176 [CRITICAL] CWE-399 CVE-2012-0176: Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attac
Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka "Silverlight Double-Free Vulnerability."
nvd
CVE-2013-3178P3CRITICALCVSS 9.3v5.0.60401.0v5.0.60818.0+3 more2013-07-10
CVE-2013-3178 [CRITICAL] CWE-94 CVE-2013-3178: Microsoft Silverlight 5 before 5.1.20513.0 does not properly initialize arrays, which allows remote
Microsoft Silverlight 5 before 5.1.20513.0 does not properly initialize arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via a crafted Silverlight application, aka "Null Pointer Vulnerability."
nvd
CVE-2012-0014P3HIGHCVSS 7.8v4.0.50524.00v4.0.50826.0+8 more2012-02-14
CVE-2012-0014 [HIGH] CWE-94 CVE-2012-0014: Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properl
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4
nvd
CVE-2011-1253P3CRITICALCVSS 9.3v4.0.60531.02011-10-12
CVE-2011-1253 [CRITICAL] CWE-264 CVE-2011-1253: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silv
nvd
CVE-2010-0019P3CRITICALCVSS 9.3≤ 3.0.40818.0v3.0.40624.00+3 more2010-08-11
CVE-2010-0019 [CRITICAL] CWE-94 CVE-2010-0019: Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not
Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
nvd
CVE-2015-6166P3CRITICALCVSS 9.3v5.02015-12-09
CVE-2015-6166 [CRITICAL] CWE-119 CVE-2015-6166: Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cau
Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or write access) via unspecified open and close requests, aka "Microsoft Silverlight RCE Vulnerability."
nvd
CVE-2015-1715P3CRITICALCVSS 9.3≤ 5.1.30214.02015-05-13
CVE-2015-1715 [CRITICAL] CWE-264 CVE-2015-1715: Microsoft Silverlight 5 before 5.1.40416.00 allows remote attackers to bypass intended integrity-lev
Microsoft Silverlight 5 before 5.1.40416.00 allows remote attackers to bypass intended integrity-level restrictions via a crafted Silverlight application, aka "Microsoft Silverlight Out of Browser Application Vulnerability."
nvd
CVE-2011-1845P3HIGHCVSS 7.8≤ 4.0.60129.0v2.0.31005.00+5 more2011-05-03
CVE-2011-1845 [HIGH] CWE-399 CVE-2011-1845: Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.6
Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.
nvd
CVE-2011-1844P3HIGHCVSS 7.8≤ 4.0.60129.0v2.0.31005.00+5 more2011-05-03
CVE-2011-1844 [HIGH] CWE-399 CVE-2011-1844: Memory leak in Microsoft Silverlight 4 before 4.0.60310.0 allows remote attackers to cause a denial
Memory leak in Microsoft Silverlight 4 before 4.0.60310.0 allows remote attackers to cause a denial of service (memory consumption) via an application involving a popup control and a custom DependencyProperty property, related to lack of garbage collection.
nvd
CVE-2014-0319P3HIGHCVSS 7.1v5.0.60401.0v5.0.60818.0+5 more2014-03-12
CVE-2014-0319 [HIGH] CWE-264 CVE-2014-0319: Microsoft Silverlight 5 before 5.1.30214.0 and Silverlight 5 Developer Runtime before 5.1.30214.0 al
Microsoft Silverlight 5 before 5.1.30214.0 and Silverlight 5 Developer Runtime before 5.1.30214.0 allow attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors, aka "Silverlight DEP/ASLR Bypass Vulnerability."
nvd
CVE-2015-6114P4MEDIUMCVSS 4.3v5.02015-12-09
CVE-2015-6114 [MEDIUM] CWE-200 CVE-2015-6114: Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection me
Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6165.
nvd
CVE-2015-6165P4MEDIUMCVSS 4.3v5.02015-12-09
CVE-2015-6165 [MEDIUM] CVE-2015-6165: Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection me
Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6114.
nvd
← Previous2 / 2