« Volver al listado

CVE-2011-1844

Estado: ModificadaAlta (7.8)—

Memory leak in Microsoft Silverlight 4 before 4.0.60310.0 allows remote attackers to cause a denial of service (memory consumption) via an application involving a popup control and a custom DependencyProperty property, related to lack of garbage collection.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-1844",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-05-03T19:55:13.447",
  "references": [
    {
      "url": "http://isc.sans.edu/diary.html?storyid=10747",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.microsoft.com/kb/2526954",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://isc.sans.edu/diary.html?storyid=10747",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.microsoft.com/kb/2526954",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Memory leak in Microsoft Silverlight 4 before 4.0.60310.0 allows remote attackers to cause a denial of service (memory consumption) via an application involving a popup control and a custom DependencyProperty property, related to lack of garbage collection."
    },
    {
      "lang": "es",
      "value": "Fallo de memoria en Microsoft Silverlight v4 antes de v4.0.60310.0 permite a atacantes remotos provocar una denegación de servicio (por consumo de memoria), por un fallo en la recolección de basura por parte del recolector a través de una aplicación que implique un control emergente con una propiedad DependencyProperty modificada."
    }
  ],
  "lastModified": "2026-06-16T23:30:13.787",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:silverlight:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4DDD4AC-347A-4B3E-84C3-BDBFB5A87536",
              "versionEndIncluding": "4.0.60129.0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:silverlight:2.0.31005.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A20AA4A5-B6DA-42F5-ADA6-CE8F3D08DAEB"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:silverlight:2.0.40115.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F90BA702-AEA8-4CFA-8FE7-85EC3C36C893"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:silverlight:3.0.40624.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D5F951F-6DCB-4651-A99A-C7237025E00C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:silverlight:3.0.40723.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAAF6291-8E80-4DE5-820C-BA9778822194"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:silverlight:3.0.40818.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AB865CD-A8EC-4341-9DF8-D4D92351EE1D"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:silverlight:3.0.50106.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA1230C5-DF32-438C-BE83-6239E7D0366A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}