← Back to browse · API

CVE-2013-0006

Severity
HIGH
CVSS
8.8
EPSS
0.28084
Risk score
45.03
CISA KEV
No
PoC
No
Published
2013-01-09
Modified
2025-01-16
First seen
2026-08-07
Aliases
EUVD-2013-0049, GHSA-4JCP-W4PP-VM92
Products
n/a:n/a n/a
Sources
euvd EUVD-2013-0049

Description

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

References