threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft .net framework
Product
microsoft .net framework
181 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-33116
all versions
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to d
7.5
HIGH
CVE-2026-32226
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthoriz
5.9
MEDIUM
CVE-2026-23666
all versions
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
7.5
HIGH
CVE-2025-55248
all versions
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a
4.8
MEDIUM
CVE-2025-21176
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43484
all versions
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2024-43483
all versions
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2024-38081
all versions
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
7.3
HIGH
CVE-2024-21409
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.3
HIGH
CVE-2024-29059
all versions
.NET Framework Information Disclosure Vulnerability
7.5
HIGH
CVE-2024-21312
all versions
.NET Framework Denial of Service Vulnerability
7.5
HIGH
CVE-2024-0057
>= 4.8 and < 4.8.04690.02
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
9.1
CRITICAL
CVE-2024-0056
>= 4.8 and < 4.8.04690.02
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
8.7
HIGH
CVE-2023-36049
all versions
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
7.6
HIGH
CVE-2023-36560
all versions
ASP.NET Security Feature Bypass Vulnerability
8.8
HIGH
CVE-2023-36796
all versions
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36794
all versions
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36793
all versions
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36792
all versions
Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36788
all versions
.NET Framework Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-36899
all versions
ASP.NET Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2023-36873
all versions
.NET Framework Spoofing Vulnerability
7.4
HIGH
CVE-2023-32030
all versions
.NET and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2023-29331
all versions
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2023-29326
all versions
.NET Framework Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-24936
all versions
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
7.5
HIGH
CVE-2023-24897
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-24895
all versions
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-21808
all versions
.NET and Visual Studio Remote Code Execution Vulnerability
7.8
HIGH
CVE-2023-21722
all versions
.NET Framework Denial of Service Vulnerability
5.0
MEDIUM
CVE-2022-41089
all versions
.NET Framework Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-41064
all versions
.NET Framework Information Disclosure Vulnerability
5.8
MEDIUM
CVE-2022-26929
all versions
.NET Framework Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-30130
all versions
.NET Framework Denial of Service Vulnerability
3.3
LOW
CVE-2022-26832
all versions
.NET Framework Denial of Service Vulnerability
7.5
HIGH
CVE-2022-21911
all versions
.NET Framework Denial of Service Vulnerability
7.5
HIGH
CVE-2021-24111
all versions
.NET Framework Denial of Service Vulnerability
7.5
HIGH
CVE-2020-16937
all versions
<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who su
4.7
MEDIUM
CVE-2020-1476
all versions
An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cac
5.5
MEDIUM
CVE-2020-1046
all versions
A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited
7.8
HIGH
CVE-2020-1147
all versions
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to
7.8
HIGH
CVE-2020-1108
all versions
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET F
7.5
HIGH
CVE-2020-1066
all versions
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To
7.8
HIGH
CVE-2020-0646
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framewo
9.8
CRITICAL
CVE-2020-0606
all versions
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An atta
8.8
HIGH
CVE-2020-0605
all versions
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An atta
8.8
HIGH
CVE-2019-1142
all versions
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbit
5.5
MEDIUM
CVE-2019-1113
all versions
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An atta
8.8
HIGH
CVE-2019-1083
all versions
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET D
7.5
HIGH
CVE-2019-1006
all versions
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), all
7.5
HIGH
CVE-2019-0981
all versions
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and
7.5
HIGH
CVE-2019-0980
all versions
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and
7.5
HIGH
CVE-2019-0864
all versions
A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial
5.5
MEDIUM
CVE-2019-0820
all versions
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework a
7.5
HIGH
CVE-2019-11397
all versions
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inc
6.5
MEDIUM
CVE-2019-0657
all versions
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visu
5.9
MEDIUM
CVE-2019-0613
all versions
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the sou
8.8
HIGH
CVE-2019-0545
all versions
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharin
7.5
HIGH
CVE-2018-8540
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framewo
9.8
CRITICAL
CVE-2018-8517
all versions
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial O
7.5
HIGH
CVE-2018-8421
all versions
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote C
9.8
CRITICAL
CVE-2018-8360
all versions
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in m
7.5
HIGH
CVE-2018-8356
all versions
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, ak
5.5
MEDIUM
CVE-2018-8284
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framewo
8.1
HIGH
CVE-2018-8260
all versions
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".
8.8
HIGH
CVE-2018-8202
all versions
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, a
7.8
HIGH
CVE-2018-1039
all versions
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET F
7.8
HIGH
CVE-2018-0765
all versions
A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial
7.5
HIGH
CVE-2018-0786
all versions
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell
7.5
HIGH
CVE-2018-0764
all versions
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0
7.5
HIGH
CVE-2017-8759
all versions
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malici
7.8
HIGH
CVE-2017-8585
all versions
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application
7.5
HIGH
CVE-2017-0248
all versions
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage tag
7.5
HIGH
CVE-2017-0160
all versions
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute
7.8
HIGH
CVE-2016-7270
all versions
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attack
7.5
HIGH
CVE-2016-3209
all versions
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Win
5.5
MEDIUM
CVE-2016-3255
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data c
7.5
HIGH
CVE-2016-0149
all versions
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitiv
5.9
MEDIUM
CVE-2016-0148
all versions
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted appli
7.8
HIGH
CVE-2016-0145
all versions
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 20
8.8
HIGH
CVE-2016-0132
all versions
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified eleme
9.8
CRITICAL
CVE-2016-0047
all versions
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive inform
7.5
HIGH
CVE-2016-0033
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, whi
7.5
HIGH
CVE-2015-6108
all versions
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1
CVE-2015-6115
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 allows remote attackers to bypass the ASLR protection mechanism via a crafted web
CVE-2015-6099
all versions
Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attack
CVE-2015-6096
all versions
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read
CVE-2015-2526
all versions
Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site vi
CVE-2015-2504
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array c
CVE-2015-2481
all versions
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote
CVE-2015-2480
all versions
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote
CVE-2015-2479
all versions
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote
CVE-2015-2464
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2463
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2462
all versions
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
CVE-2015-2460
all versions
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
CVE-2015-2456
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2455
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-2435
all versions
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a
CVE-2015-1673
all versions
The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allo
CVE-2015-1672
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recur
CVE-2015-1671
all versions
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP
7.8
HIGH
CVE-2015-1670
all versions
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote
CVE-2015-1648
all versions
ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is
CVE-2014-4149
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks,
CVE-2014-4122
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain pote
CVE-2014-4121
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifi
CVE-2014-4073
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the Click
CVE-2014-4072
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for re
CVE-2014-4062
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, and 3.5.1 does not properly implement the ASLR protection mechanism, whic
CVE-2014-1806
all versions
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly res
CVE-2014-0295
all versions
VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier
CVE-2014-0257
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe t
CVE-2014-0253
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which
CVE-2013-3861
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (applicatio
CVE-2013-3860
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature valid
CVE-2013-3128
all versions
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
CVE-2013-3171
all versions
The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the p
CVE-2013-3134
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properl
CVE-2013-3133
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, w
CVE-2013-3132
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that
CVE-2013-3131
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes
CVE-2013-3129
all versions
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers,
7.8
HIGH
CVE-2013-1337
all versions
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoi
CVE-2013-1336
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures,
CVE-2013-0073
all versions
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict
CVE-2013-0005
all versions
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and
CVE-2013-0004
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of
CVE-2013-0003
all versions
Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.
CVE-2013-0002
all versions
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5,
CVE-2013-0001
all versions
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not pro
CVE-2012-4777
all versions
The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce obj
CVE-2012-4776
all versions
The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate co
CVE-2012-2519
all versions
Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5
CVE-2012-1896
all versions
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allow
CVE-2012-1895
all versions
The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object
CVE-2012-1855
all versions
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers
CVE-2012-0164
all versions
Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (app
CVE-2012-0162
all versions
Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a c
CVE-2012-0161
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified excepti
CVE-2012-0160
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which a
CVE-2012-0163
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which a
CVE-2012-0015
all versions
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote at
CVE-2012-0014
all versions
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory as
7.8
HIGH
CVE-2011-1253
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict i
CVE-2011-1978
all versions
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote
CVE-2011-1977
all versions
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly
CVE-2011-0664
all versions
Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properl
CVE-2011-1271
all versions
The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not prop
7.7
HIGH
CVE-2010-3958
all versions
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which
CVE-2010-3228
all versions
The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote
CVE-2010-3332
all versions
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Informa
CVE-2010-1898
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight
CVE-2010-2085
<= 1.0
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which
CVE-2009-3126
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Micros
CVE-2009-2528
all versions
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote atta
CVE-2009-2504
all versions
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Window
CVE-2009-2503
all versions
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 M
CVE-2009-2502
all versions
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microso
8.1
HIGH
CVE-2009-2501
all versions
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2
CVE-2009-2500
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Micros
CVE-2009-2497
all versions
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not
CVE-2009-0091
all versions
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable cod
CVE-2009-0090
all versions
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attack
CVE-2009-1536
all versions
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does
CVE-2008-5100
all versions
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedde
CVE-2008-3843
all versions
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not prop
CVE-2008-3842
all versions
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not p
CVE-2007-0043
all versions
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista
CVE-2007-0042
all versions
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allo
CVE-2007-0041
all versions
The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote att
CVE-2006-7192
all versions
Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/
/) enclosures, which allows remote attackers to by
CVE-2006-3436
all versions
Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or
CVE-2006-1300
all versions
Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote atta
CVE-2006-1511
all versions
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute
CVE-2006-1510
all versions
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the
CVE-2005-2127
all versions
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly
CVE-2005-0509
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to i
CVE-2004-0200
all versions
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, all
CVE-2002-0409
all versions
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows
CVE-2002-0369
all versions
Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbi
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin