Home/Product/microsoft .net framework
Product

microsoft .net framework

181 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33116
all versions
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to d
7.5HIGH
CVE-2026-32226
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthoriz
5.9MEDIUM
CVE-2026-23666
all versions
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
7.5HIGH
CVE-2025-55248
all versions
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a
4.8MEDIUM
CVE-2025-21176
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
8.8HIGH
CVE-2024-43484
all versions
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
7.5HIGH
CVE-2024-43483
all versions
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
7.5HIGH
CVE-2024-38081
all versions
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
7.3HIGH
CVE-2024-21409
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.3HIGH
CVE-2024-29059
all versions
.NET Framework Information Disclosure Vulnerability
7.5HIGH
CVE-2024-21312
all versions
.NET Framework Denial of Service Vulnerability
7.5HIGH
CVE-2024-0057
>= 4.8 and < 4.8.04690.02
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
9.1CRITICAL
CVE-2024-0056
>= 4.8 and < 4.8.04690.02
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
8.7HIGH
CVE-2023-36049
all versions
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
7.6HIGH
CVE-2023-36560
all versions
ASP.NET Security Feature Bypass Vulnerability
8.8HIGH
CVE-2023-36796
all versions
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36794
all versions
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36793
all versions
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36792
all versions
Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36788
all versions
.NET Framework Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36899
all versions
ASP.NET Elevation of Privilege Vulnerability
8.8HIGH
CVE-2023-36873
all versions
.NET Framework Spoofing Vulnerability
7.4HIGH
CVE-2023-32030
all versions
.NET and Visual Studio Denial of Service Vulnerability
7.5HIGH
CVE-2023-29331
all versions
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
7.5HIGH
CVE-2023-29326
all versions
.NET Framework Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-24936
all versions
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
7.5HIGH
CVE-2023-24897
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-24895
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-21808
all versions
.NET and Visual Studio Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-21722
all versions
.NET Framework Denial of Service Vulnerability
5.0MEDIUM
CVE-2022-41089
all versions
.NET Framework Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-41064
all versions
.NET Framework Information Disclosure Vulnerability
5.8MEDIUM
CVE-2022-26929
all versions
.NET Framework Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-30130
all versions
.NET Framework Denial of Service Vulnerability
3.3LOW
CVE-2022-26832
all versions
.NET Framework Denial of Service Vulnerability
7.5HIGH
CVE-2022-21911
all versions
.NET Framework Denial of Service Vulnerability
7.5HIGH
CVE-2021-24111
all versions
.NET Framework Denial of Service Vulnerability
7.5HIGH
CVE-2020-16937
all versions
<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who su
4.7MEDIUM
CVE-2020-1476
all versions
An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cac
5.5MEDIUM
CVE-2020-1046
all versions
A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited
7.8HIGH
CVE-2020-1147
all versions
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to
7.8HIGH
CVE-2020-1108
all versions
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET F
7.5HIGH
CVE-2020-1066
all versions
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To
7.8HIGH
CVE-2020-0646
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framewo
9.8CRITICAL
CVE-2020-0606
all versions
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An atta
8.8HIGH
CVE-2020-0605
all versions
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An atta
8.8HIGH
CVE-2019-1142
all versions
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbit
5.5MEDIUM
CVE-2019-1113
all versions
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An atta
8.8HIGH
CVE-2019-1083
all versions
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET D
7.5HIGH
CVE-2019-1006
all versions
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), all
7.5HIGH
CVE-2019-0981
all versions
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and
7.5HIGH
CVE-2019-0980
all versions
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and
7.5HIGH
CVE-2019-0864
all versions
A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial
5.5MEDIUM
CVE-2019-0820
all versions
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework a
7.5HIGH
CVE-2019-11397
all versions
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inc
6.5MEDIUM
CVE-2019-0657
all versions
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visu
5.9MEDIUM
CVE-2019-0613
all versions
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the sou
8.8HIGH
CVE-2019-0545
all versions
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharin
7.5HIGH
CVE-2018-8540
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framewo
9.8CRITICAL
CVE-2018-8517
all versions
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial O
7.5HIGH
CVE-2018-8421
all versions
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote C
9.8CRITICAL
CVE-2018-8360
all versions
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in m
7.5HIGH
CVE-2018-8356
all versions
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, ak
5.5MEDIUM
CVE-2018-8284
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framewo
8.1HIGH
CVE-2018-8260
all versions
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".
8.8HIGH
CVE-2018-8202
all versions
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, a
7.8HIGH
CVE-2018-1039
all versions
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET F
7.8HIGH
CVE-2018-0765
all versions
A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial
7.5HIGH
CVE-2018-0786
all versions
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell
7.5HIGH
CVE-2018-0764
all versions
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0
7.5HIGH
CVE-2017-8759
all versions
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malici
7.8HIGH
CVE-2017-8585
all versions
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application
7.5HIGH
CVE-2017-0248
all versions
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage tag
7.5HIGH
CVE-2017-0160
all versions
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute
7.8HIGH
CVE-2016-7270
all versions
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attack
7.5HIGH
CVE-2016-3209
all versions
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Win
5.5MEDIUM
CVE-2016-3255
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data c
7.5HIGH
CVE-2016-0149
all versions
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitiv
5.9MEDIUM
CVE-2016-0148
all versions
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted appli
7.8HIGH
CVE-2016-0145
all versions
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 20
8.8HIGH
CVE-2016-0132
all versions
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified eleme
9.8CRITICAL
CVE-2016-0047
all versions
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive inform
7.5HIGH
CVE-2016-0033
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, whi
7.5HIGH
CVE-2015-6108
all versions
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1
CVE-2015-6115
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 allows remote attackers to bypass the ASLR protection mechanism via a crafted web
CVE-2015-6099
all versions
Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attack
CVE-2015-6096
all versions
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read
CVE-2015-2526
all versions
Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site vi
CVE-2015-2504
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array c
CVE-2015-2481
all versions
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote
CVE-2015-2480
all versions
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote
CVE-2015-2479
all versions
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote
CVE-2015-2464
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2463
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2462
all versions
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
CVE-2015-2460
all versions
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
CVE-2015-2456
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2455
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2435
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-1673
all versions
The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allo
CVE-2015-1672
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recur
CVE-2015-1671
all versions
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP
7.8HIGH
CVE-2015-1670
all versions
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote
CVE-2015-1648
all versions
ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is
CVE-2014-4149
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks,
CVE-2014-4122
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain pote
CVE-2014-4121
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifi
CVE-2014-4073
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the Click
CVE-2014-4072
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for re
CVE-2014-4062
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, and 3.5.1 does not properly implement the ASLR protection mechanism, whic
CVE-2014-1806
all versions
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly res
CVE-2014-0295
all versions
VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier
CVE-2014-0257
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe t
CVE-2014-0253
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which
CVE-2013-3861
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (applicatio
CVE-2013-3860
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature valid
CVE-2013-3128
all versions
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
CVE-2013-3171
all versions
The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the p
CVE-2013-3134
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properl
CVE-2013-3133
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, w
CVE-2013-3132
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that
CVE-2013-3131
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes
CVE-2013-3129
all versions
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers,
7.8HIGH
CVE-2013-1337
all versions
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoi
CVE-2013-1336
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures,
CVE-2013-0073
all versions
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict
CVE-2013-0005
all versions
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and
CVE-2013-0004
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of
CVE-2013-0003
all versions
Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.
CVE-2013-0002
all versions
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5,
CVE-2013-0001
all versions
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not pro
CVE-2012-4777
all versions
The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce obj
CVE-2012-4776
all versions
The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate co
CVE-2012-2519
all versions
Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5
CVE-2012-1896
all versions
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allow
CVE-2012-1895
all versions
The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object
CVE-2012-1855
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers
CVE-2012-0164
all versions
Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (app
CVE-2012-0162
all versions
Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a c
CVE-2012-0161
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified excepti
CVE-2012-0160
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which a
CVE-2012-0163
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which a
CVE-2012-0015
all versions
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote at
CVE-2012-0014
all versions
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory as
7.8HIGH
CVE-2011-1253
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict i
CVE-2011-1978
all versions
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote
CVE-2011-1977
all versions
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly
CVE-2011-0664
all versions
Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properl
CVE-2011-1271
all versions
The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not prop
7.7HIGH
CVE-2010-3958
all versions
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which
CVE-2010-3228
all versions
The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote
CVE-2010-3332
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Informa
CVE-2010-1898
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight
CVE-2010-2085
<= 1.0
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which
CVE-2009-3126
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Micros
CVE-2009-2528
all versions
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote atta
CVE-2009-2504
all versions
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Window
CVE-2009-2503
all versions
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 M
CVE-2009-2502
all versions
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microso
8.1HIGH
CVE-2009-2501
all versions
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2
CVE-2009-2500
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Micros
CVE-2009-2497
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not
CVE-2009-0091
all versions
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable cod
CVE-2009-0090
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attack
CVE-2009-1536
all versions
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does
CVE-2008-5100
all versions
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedde
CVE-2008-3843
all versions
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not prop
CVE-2008-3842
all versions
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not p
CVE-2007-0043
all versions
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista
CVE-2007-0042
all versions
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allo
CVE-2007-0041
all versions
The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote att
CVE-2006-7192
all versions
Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/ /) enclosures, which allows remote attackers to by
CVE-2006-3436
all versions
Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or
CVE-2006-1300
all versions
Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote atta
CVE-2006-1511
all versions
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute
CVE-2006-1510
all versions
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the
CVE-2005-2127
all versions
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly
CVE-2005-0509
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to i
CVE-2004-0200
all versions
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, all
CVE-2002-0409
all versions
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows
CVE-2002-0369
all versions
Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbi
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin