4.3
CVE-2014-4062
- EPSS 14.26%
- Veröffentlicht 12.08.2014 21:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, and 3.5.1 does not properly implement the ASLR protection mechanism, which allows remote attackers to obtain sensitive address information via a crafted web site, aka ".NET ASLR Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ .Net Framework Version 1.1 Update sp1
Microsoft ≫ .Net Framework Version 2.0 Update sp2
Microsoft ≫ .Net Framework Version 3.0 Update sp2
Microsoft ≫ .Net Framework Version 3.5
Microsoft ≫ .Net Framework Version 3.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 14.26% | 0.961 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
http://www.securityfocus.com/bid/69145
http://www.securitytracker.com/id/1030721
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-046