← Vulnerability feed

Vulnerability record · CVE-2015-6114 · published 9 December 2015

CVE-2015-6114: Microsoft silverlight information exposure vulnerability

Microsoft · Silverlight

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6165.

4.3 CVSS 2.0 Medium EPSS 19% · top 2.8% CWE-200 · Information exposure
4.3CVSS 2.0 base score
19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6165.

AV:N/AC:M/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6114 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-0034Microsoft Silverlight negative offset decoding flaw allows remote code executionMicrosoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this…KEVEPSS 69%analysed7.8CVE-2015-1671Microsoft DirectWrite TrueType Font Parsing Remote Code ExecutionThe Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution…KEVEPSS 49%analysed7.8CVE-2013-0074Microsoft Silverlight pointer validation flaw enables remote code executionMicrosoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Sil…KEVEPSS 79%analysed5.5CVE-2013-3896Microsoft Silverlight pointer validation flaw leaks sensitive informationMicrosoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight …KEVEPSS 68%analysed9.3CVE-2015-6166Microsoft silverlight memory buffer overflow vulnerabilityMicrosoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or wri…EPSS 14%9.3CVE-2015-6108Microsoft live meeting memory buffer overflow vulnerabilityThe Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 20…EPSS 26%9.3CVE-2015-2464Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 36%9.3CVE-2015-2463Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2015-6114), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.