Beschreibung
Multiple serious vulnerabilities have been found in Microsoft .NET Framework. Malicious users can exploit these vulnerabilities to cause denial of service or obtain sensitive information.
Below is a complete list of vulnerabilities
- An improper handling of XSLT can be exploited remotely via a specially designed XML content to cause denial of service;
- An improper icon data handling at Windows Forms can be exploited remotely via a specially designed icon to obtain sensitive information.
Technical details
To mitigate vulnerability (1) do not load XSL stylesheets from untrusted sources.
Vulnerability (2) can be exploited by uploading specially designed data and getting response via uploaded icon information.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2016-0033 warning
- CVE-2016-0047 warning
KB Liste
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!