CVE-2016-0034High· 8.8▾ Abyssal⚠ Exploited in the wild0dayMicrosoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverli…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 13.9 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 15, 2022
Last analysed / modified upstream
59%
59% → 70%
Added to the CISA catalog on May 25, 2022. Federal remediation due Jun 15, 2022. View catalog ↗
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
silverlight >= 5.0, < 5.1.41212.0Upgrade past the affected range:
silverlight 5.1.41212.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2013-0074High· 7.8Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Si…
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-88097High· 8.1Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62874Critical· 10.0Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85878Critical· 9.9Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.