Lucene search

K

.NET Framework Security Vulnerabilities

cve
cve

CVE-2016-0132

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Security Feature Bypass."

9.8CVSS

9.1AI Score

0.017EPSS

2016-03-09 11:59 AM
61
cve
cve

CVE-2016-0145

The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype for Business 2016; Lyn...

8.8CVSS

7.7AI Score

0.798EPSS

2016-04-12 11:59 PM
82
cve
cve

CVE-2016-0148

Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8CVSS

7.8AI Score

0.084EPSS

2016-04-12 11:59 PM
55
cve
cve

CVE-2016-0149

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure Vulnerability."

5.9CVSS

5.1AI Score

0.001EPSS

2016-05-11 01:59 AM
44
cve
cve

CVE-2016-3209

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync ...

5.5CVSS

6AI Score

0.013EPSS

2016-10-14 02:59 AM
67
cve
cve

CVE-2016-3255

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnera...

7.5CVSS

7AI Score

0.119EPSS

2016-07-13 01:59 AM
51
4
cve
cve

CVE-2016-7270

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulne...

7.5CVSS

7.3AI Score

0.039EPSS

2016-12-20 06:59 AM
63
cve
cve

CVE-2017-0160

Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."

7.8CVSS

7.8AI Score

0.049EPSS

2017-04-12 02:59 PM
80
cve
cve

CVE-2017-0248

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

7.5CVSS

7.3AI Score

0.002EPSS

2017-05-12 02:29 PM
101
cve
cve

CVE-2017-8585

Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.

7.5CVSS

6.7AI Score

0.009EPSS

2017-07-11 09:29 PM
120
cve
cve

CVE-2017-8759

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8CVSS

7.5AI Score

0.972EPSS

2017-09-13 01:29 AM
1105
In Wild
1
cve
cve

CVE-2018-0764

Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CV...

7.5CVSS

6.4AI Score

0.004EPSS

2018-01-10 01:29 AM
115
2
cve
cve

CVE-2018-0765

A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4....

7.5CVSS

7.2AI Score

0.004EPSS

2018-05-09 07:29 PM
132
cve
cve

CVE-2018-0786

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."

7.5CVSS

6.2AI Score

0.003EPSS

2018-01-10 01:29 AM
84
cve
cve

CVE-2018-1039

A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Mi...

7.8CVSS

7.3AI Score

0.001EPSS

2018-05-09 07:29 PM
54
cve
cve

CVE-2018-8202

An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7...

7.8CVSS

6.6AI Score

0.001EPSS

2018-07-11 12:29 AM
62
cve
cve

CVE-2018-8260

A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.

8.8CVSS

8AI Score

0.129EPSS

2018-07-11 12:29 AM
49
cve
cve

CVE-2018-8284

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microso...

8.1CVSS

7.3AI Score

0.191EPSS

2018-07-11 12:29 AM
69
cve
cve

CVE-2018-8356

A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2...

5.5CVSS

6.3AI Score

0.002EPSS

2018-07-11 12:29 AM
86
cve
cve

CVE-2018-8360

An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5,...

7.5CVSS

6AI Score

0.023EPSS

2018-08-15 05:29 PM
71
cve
cve

CVE-2018-8421

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework...

9.8CVSS

8.8AI Score

0.373EPSS

2018-09-13 12:29 AM
103
2
cve
cve

CVE-2018-8517

A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6...

7.5CVSS

8.1AI Score

0.001EPSS

2018-12-12 12:29 AM
73
cve
cve

CVE-2018-8540

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NE...

9.8CVSS

9.6AI Score

0.012EPSS

2018-12-12 12:29 AM
109
cve
cve

CVE-2019-0545

An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .N...

7.5CVSS

6.7AI Score

0.019EPSS

2019-01-08 09:29 PM
105
cve
cve

CVE-2019-0613

A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework and Visual...

8.8CVSS

9.3AI Score

0.03EPSS

2019-03-06 12:00 AM
88
cve
cve

CVE-2019-0657

A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.

5.9CVSS

6.7AI Score

0.003EPSS

2019-03-06 12:00 AM
108
cve
cve

CVE-2019-0820

A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.

7.5CVSS

7.2AI Score

0.002EPSS

2019-05-16 07:29 PM
156
cve
cve

CVE-2019-0864

A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial of Service Vulnerability'.

5.5CVSS

6AI Score

0.0004EPSS

2019-05-16 07:29 PM
93
cve
cve

CVE-2019-0980

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.

7.5CVSS

7.3AI Score

0.002EPSS

2019-05-16 07:29 PM
147
cve
cve

CVE-2019-0981

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.

7.5CVSS

7.3AI Score

0.002EPSS

2019-05-16 07:29 PM
135
cve
cve

CVE-2019-1006

An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.

7.5CVSS

7.8AI Score

0.002EPSS

2019-07-15 07:15 PM
210
cve
cve

CVE-2019-1083

A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.

7.5CVSS

7.2AI Score

0.001EPSS

2019-07-15 07:15 PM
172
cve
cve

CVE-2019-1113

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.

8.8CVSS

8.3AI Score

0.044EPSS

2019-07-29 02:09 PM
154
cve
cve

CVE-2019-11397

GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.

6.5CVSS

6.4AI Score

0.001EPSS

2019-05-14 09:29 PM
77
cve
cve

CVE-2019-1142

An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.

5.5CVSS

6.8AI Score

0.0004EPSS

2019-09-11 10:15 PM
138
cve
cve

CVE-2020-0605

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. ...

8.8CVSS

8.8AI Score

0.044EPSS

2020-01-14 11:15 PM
234
1
cve
cve

CVE-2020-0606

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. ...

8.8CVSS

8.8AI Score

0.044EPSS

2020-01-14 11:15 PM
165
cve
cve

CVE-2020-0646

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

9.8CVSS

9.7AI Score

0.975EPSS

2020-01-14 11:15 PM
1245
In Wild
16
cve
cve

CVE-2020-1046

A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system.To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web ...

7.8CVSS

7.9AI Score

0.015EPSS

2020-08-17 07:15 PM
142
cve
cve

CVE-2020-1066

An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcti...

7.8CVSS

7.5AI Score

0.0004EPSS

2020-05-21 11:15 PM
98
cve
cve

CVE-2020-1108

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.

7.5CVSS

7.3AI Score

0.001EPSS

2020-05-21 11:15 PM
180
cve
cve

CVE-2020-1147

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

7.8CVSS

8.1AI Score

0.868EPSS

2020-07-14 11:15 PM
1146
In Wild
2
cve
cve

CVE-2020-1476

An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files.To exploit this vulnerability, an attacker would need to send ...

5.5CVSS

6AI Score

0.0004EPSS

2020-08-17 07:15 PM
155
cve
cve

CVE-2020-16937

<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p><p>To exploit the vulnerability, an authenticated attacker would need t...

4.7CVSS

5.2AI Score

0.0004EPSS

2020-10-16 11:15 PM
156
cve
cve

CVE-2021-1725

Bot Framework SDK Information Disclosure Vulnerability

5.5CVSS

5.3AI Score

0.0004EPSS

2021-01-12 08:15 PM
83
2
cve
cve

CVE-2021-24111

.NET Framework Denial of Service Vulnerability

7.5CVSS

7.3AI Score

0.002EPSS

2021-02-25 11:15 PM
106
3
cve
cve

CVE-2021-43225

Bot Framework SDK Remote Code Execution Vulnerability

9.8CVSS

9.6AI Score

0.028EPSS

2021-12-15 03:15 PM
58
cve
cve

CVE-2022-21911

.NET Framework Denial of Service Vulnerability

7.5CVSS

7.7AI Score

0.001EPSS

2022-01-11 09:15 PM
118
cve
cve

CVE-2022-26832

.NET Framework Denial of Service Vulnerability

7.5CVSS

7.3AI Score

0.002EPSS

2022-04-15 07:15 PM
77
cve
cve

CVE-2022-26929

.NET Framework Remote Code Execution Vulnerability

7.8CVSS

8.7AI Score

0.002EPSS

2022-09-13 07:15 PM
80
4
Total number of security vulnerabilities176