cbcvebase.

Microsoft Net Framework 2.0 Service Pack 2 vulnerabilities

26 known vulnerabilities affecting microsoft/microsoft_net_framework_2.0_service_pack_2.

Total CVEs
26
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH20MEDIUM4

Vulnerabilities

Page 1 of 2
CVE-2024-29059P1HIGHCVSS 7.5KEVPoC≥ 2.0.0, < 3.0.50727.89762024-03-23
CVE-2024-29059 [HIGH] CWE-209 CVE-2024-29059: .NET Framework Information Disclosure Vulnerability .NET Framework Information Disclosure Vulnerability
nvd
CVE-2023-36899HIGHCVSS 8.8ExploitedPoC≥ 2.0.0, < 2.0.50727.89742023-08-08
CVE-2023-36899 [HIGH] CWE-20 ASP.NET Elevation of Privilege Vulnerability ASP.NET Elevation of Privilege Vulnerability ASP.NET Elevation of Privilege Vulnerability
cvelistv5
CVE-2023-36049P3CRITICALCVSS 9.8≥ 2.0.0, < 3.0.50727.89752023-11-14
CVE-2023-36049 [CRITICAL] CWE-20 CVE-2023-36049: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2024-0057P3CRITICALCVSS 9.8≥ 2.0.0, < 3.0.50727.89762024-01-09
CVE-2024-0057 [CRITICAL] CWE-20 CVE-2024-0057: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
nvd
CVE-2024-0056P3HIGHCVSS 8.7≥ 2.0.0, < 3.0.50727.89762024-01-09
CVE-2024-0056 [HIGH] CWE-319 CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnera Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
nvd
CVE-2020-1046P3HIGHCVSS 7.8≥ 2.0.0, < publication2020-08-17
CVE-2020-1046 [HIGH] CVE-2020-1046: A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attac A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application. The security update addresses the vulnerability by
nvd
CVE-2023-24936P3HIGHCVSS 7.5≥ 2.0.0, < 3.0.6920.8954; 2.0.50727.89702023-06-14
CVE-2023-24936 [HIGH] CVE-2023-24936: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-36788P3HIGHCVSS 7.8≥ 2.0.0, < 3.0.30729.89572023-09-12
CVE-2023-36788 [HIGH] CVE-2023-36788: .NET Framework Remote Code Execution Vulnerability .NET Framework Remote Code Execution Vulnerability
nvd
CVE-2023-24895P3HIGHCVSS 7.8≥ 2.0.0, < 3.0.6920.8954; 2.0.50727.89702023-06-14
CVE-2023-24895 [HIGH] CVE-2023-24895: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-29326P3HIGHCVSS 7.8≥ 2.0.0, < 3.0.6920.8954; 2.0.50727.89702023-06-14
CVE-2023-29326 [HIGH] CVE-2023-29326: .NET Framework Remote Code Execution Vulnerability .NET Framework Remote Code Execution Vulnerability
nvd
CVE-2022-41089P3HIGHCVSS 7.8≥ 2.0.0, < 30729.89532022-12-13
CVE-2022-41089 [HIGH] CVE-2022-41089: .NET Framework Remote Code Execution Vulnerability .NET Framework Remote Code Execution Vulnerability
nvd
CVE-2024-43484P3HIGHCVSS 7.5≥ 2.0.0, < 3.0.30729.89742024-10-08
CVE-2024-43484 [HIGH] CWE-407 CVE-2024-43484: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-43483P3HIGHCVSS 7.5≥ 2.0.0, < 3.0.30729.89742024-10-08
CVE-2024-43483 [HIGH] CWE-407 CVE-2024-43483: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2023-29331P3HIGHCVSS 7.5≥ 2.0.0, < 3.0.6920.8954; 2.0.50727.89702023-06-14
CVE-2023-29331 [HIGH] CWE-400 CVE-2023-29331: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2023-32030P3HIGHCVSS 7.5≥ 2.0.0, < 10.0.14393.59892023-06-14
CVE-2023-32030 [HIGH] CVE-2023-32030: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2025-55248P4MEDIUMCVSS 5.7≥ 2.0.0, < 2.0.50727.89812025-10-14
CVE-2025-55248 [MEDIUM] CWE-326 CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
nvd
CVE-2020-1476P4MEDIUMCVSS 5.5≥ 2.0.0, < publication2020-08-17
CVE-2020-1476 [MEDIUM] CVE-2020-1476: An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an attacker would need to send a specially crafted request to an affected server. The update
nvd
CVE-2020-16937P4MEDIUMCVSS 5.5≥ 2.0.0, < publication2020-10-16
CVE-2020-16937 [MEDIUM] CVE-2020-16937: <p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory. To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application. The update addresses the vulne
nvd
CVE-2023-36560HIGHCVSS 8.8≥ 2.0.0, < 3.0.50727.89752023-11-14
CVE-2023-36560 [HIGH] ASP.NET Security Feature Bypass Vulnerability ASP.NET Security Feature Bypass Vulnerability ASP.NET Security Feature Bypass Vulnerability
cvelistv5
CVE-2022-26832HIGHCVSS 7.5≥ 2.0.0, < 2.0.50727.89622022-04-15
CVE-2022-26832 [HIGH] .NET Framework Denial of Service Vulnerability .NET Framework Denial of Service Vulnerability .NET Framework Denial of Service Vulnerability
cvelistv5
Microsoft Net Framework 2.0 Service Pack 2 vulnerabilities | cvebase