← Back

CVE-2015-6096

nvd nist
Published: Nov 11, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."

Affected (8)

1 product
.net Framework
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2.0 sp2
Version 3.5.1
Version 3.5
Version 4.0
Version 4.5.1
Version 4.5.2
Version 4.5
Version 4.6

Timeline

No history available yet.