Microsoft Asp.Net vulnerabilities

9 known vulnerabilities affecting microsoft/asp.net.

Total CVEs
9
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2018-8171HIGHCVSS 7.5vWeb Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5vWeb Pages 3.2.3 on Microsoft Visual Studio 2015 Update 32018-07-11
CVE-2018-8171 [HIGH] CWE-287 CVE-2018-8171: A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempt A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
cvelistv5nvd
CVE-2010-2084MEDIUMCVSS 4.3v2.02010-05-27
CVE-2010-2084 [MEDIUM] CWE-79 CVE-2010-2084: Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits fro Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
nvd
CVE-2010-2088MEDIUMCVSS 4.3v3.52010-05-27
CVE-2010-2088 [MEDIUM] CWE-79 CVE-2010-2088: ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remot ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWSTATE parameter.
nvd
CVE-2006-1364HIGHCVSS 7.5PoC≤ 1.1v1.12006-03-23
CVE-2006-1364 [HIGH] CWE-400 CVE-2006-1364: Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under t
nvd
CVE-2005-1665MEDIUMCVSS 5.0v1.0v1.12005-05-18
CVE-2005-1665 [MEDIUM] CVE-2005-1665: The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows re The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.
nvd
CVE-2005-1664MEDIUMCVSS 6.4v1.0v1.12005-05-18
CVE-2005-1664 [MEDIUM] CVE-2005-1664: The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay att The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) reuse ViewState information after the application's state has changed, or (3) use the ViewState to conduct attacks or expose content to third parties.
nvd
CVE-2005-0452MEDIUMCVSS 4.3PoCv1.0v1.12005-02-16
CVE-2005-0452 [MEDIUM] CVE-2005-0452: Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 a Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
nvd
CVE-2004-0847CRITICALCVSS 9.8PoC≤ 1.1v1.12004-11-03
CVE-2004-0847 [CRITICAL] CWE-22 CVE-2004-0847: The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass aut The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."
nvd
CVE-2003-0768MEDIUMCVSS 6.8v1.12003-09-22
CVE-2003-0768 [MEDIUM] CVE-2003-0768: Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script In Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.
nvd