6.5
CVE-2019-1079
- EPSS 25.34%
- Veröffentlicht 15.07.2019 19:15:17
- Zuletzt bearbeitet 21.11.2024 04:35:58
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Visual Studio Version2010 Updatesp1
Microsoft ≫ Visual Studio Version2012 Updateupdate_5
Microsoft ≫ Visual Studio Version2013 Updateupdate_5
Microsoft ≫ Visual Studio Version2015 Updateupdate_3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 25.34% | 0.96 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.