CVE Vulnerabilities

CVE-2014-4122

Published: Oct 15, 2014 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable images location, aka .NET ASLR Vulnerability.

Affected Software

Name Vendor Start Version End Version
.net_framework Microsoft 2.0-sp2 (including) 2.0-sp2 (including)
.net_framework Microsoft 3.5 (including) 3.5 (including)
.net_framework Microsoft 3.5.1 (including) 3.5.1 (including)

References