CVE Vulnerabilities

CVE-2014-0295

Published: Feb 12, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka VSAVB7RT ASLR Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
.net_frameworkMicrosoft2.0-sp2 (including)2.0-sp2 (including)
.net_frameworkMicrosoft3.5.1 (including)3.5.1 (including)

References