CVE-2006-1510
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 13.67% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/.net framework
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044482.htmlExploit, Patch, Vendor Advisory
- http://owasp.net/forums/234/showpost.aspxExploit, Patch
- http://owasp.net/forums/257/showpost.aspxExploit
- http://secunia.com/advisories/19406Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/17243Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1113
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25439
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044482.htmlExploit, Patch, Vendor Advisory
- http://owasp.net/forums/234/showpost.aspxExploit, Patch
- http://owasp.net/forums/257/showpost.aspxExploit
- http://secunia.com/advisories/19406Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/17243Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1113
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25439
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.