← Back

CVE-2013-0006

nvd nist
Published: Jan 9, 2013Modified: Apr 29, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

Affected (29)

15 products
Xml Core Services
Windows 7
Windows 8
Windows Server 2008
Windows Server 2012
Windows Xp
Windows Rt
Windows Server 2003
Windows Vista
Expression Web
Groove Server
Office
Office Compatibility Pack
Sharepoint Server
Word Viewer
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
All versions
All versions
Microsoft
All versions
All versions
Version r2
All versions
All versions
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 4.0
Version 6.0
All versions
All versions
All versions
All versions
All versions
All versions
Configuration C
13 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0
Microsoft
All versions
Version 2
Microsoft
Version 2007 sp2
Version 2007 sp3
Microsoft
Version 2003 sp3
Version 2007 sp2
Version 2007 sp3
Microsoft
All versions
All versions
Microsoft
Version 2007 sp2
Version 2007 sp3
All versions

Related CWEs

Timeline

No history available yet.