← Back

CVE-2013-3860

nvd nist
Published: Oct 9, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML document, aka "Entity Expansion Vulnerability."

Affected (6)

1 product
.net Framework
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2.0 sp2
Version 3.5.1
Version 3.5
Version 3.5 sp1
Version 4.0
Version 4.5

Timeline

No history available yet.