Vulnerability Description
Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Silverlight | <= 4.0.60129.0 |
Related Weaknesses (CWE)
References
- http://isc.sans.edu/diary.html?storyid=10747Patch
- http://support.microsoft.com/kb/2526954Patch
- http://isc.sans.edu/diary.html?storyid=10747Patch
- http://support.microsoft.com/kb/2526954Patch
FAQ
What is CVE-2011-1845?
CVE-2011-1845 is a vulnerability with a CVSS score of 7.8 (HIGH). Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application i...
How severe is CVE-2011-1845?
CVE-2011-1845 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1845?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Silverlight.