7.8
CVE-2013-0005
- EPSS 32.1%
- Veröffentlicht 09.01.2013 18:09:40
- Zuletzt bearbeitet 16.06.2026 23:48:41
- Erkennungen
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ .Net Framework Version 3.5
Microsoft ≫ .Net Framework Version 3.5 Update sp1
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version sp2 Update professional Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Windows Xp Version sp2 Update professional Edition x64
Microsoft ≫ .Net Framework Version 3.5.1
Microsoft ≫ Windows 7 Update sp1 Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows 7 Version -
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition itanium
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows 7 Version -
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition itanium
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition x64
Microsoft ≫ .Net Framework Version 4.0
Microsoft ≫ Windows 7 Update sp1 Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows 7 Version -
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition itanium
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition x64
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Windows Xp Version sp2 Update professional Edition x64
Microsoft ≫ Windows 7 Update sp1 Edition x86
Microsoft ≫ Windows 7 Version -
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
Microsoft ≫ Windows Server 2008 Version - Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition itanium
Microsoft ≫ Windows Server 2008 Version r2 Update - Edition x64
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Windows Xp Version sp2 Update professional Edition x64
Microsoft ≫ Management Odata Iis Extension Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 32.1% | 0.981 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.us-cert.gov/cas/techalerts/TA13-008A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-007
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16282