cbcvebase.

Microsoft Net Framework vulnerabilities

185 known vulnerabilities affecting microsoft/net_framework.

Total CVEs
185
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH79MEDIUM41LOW2

Vulnerabilities

Page 10 of 10
CVE-2005-0509P4MEDIUMCVSS 4.3v1.0v1.12005-03-14
CVE-2005-0509 [MEDIUM] CVE-2005-0509: Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Ne Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
nvd
CVE-2006-1511P4MEDIUMCVSS 5.1v1.0v1.12006-03-30
CVE-2006-1511 [MEDIUM] CVE-2006-1511: Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user- Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
nvd
CVE-2018-8356P4MEDIUMCVSS 5.5v3.0-sp2v3.5+9 more2018-07-11
CVE-2018-8356 [MEDIUM] CWE-295 CVE-2018-8356: A security feature bypass vulnerability exists when Microsoft .NET Framework components do not corre A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, AS
nvd
CVE-2010-2085P4MEDIUMCVSS 4.3≤ 1.0v1.02010-05-27
CVE-2010-2085 [MEDIUM] CWE-79 CVE-2010-2085: The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the Enabl The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.
nvd
CVE-2019-0864P4MEDIUMCVSS 5.5v2.0v3.0+10 more2019-05-16
CVE-2019-0864 [MEDIUM] CVE-2019-0864: A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memo A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial of Service Vulnerability'.
nvd
Microsoft Net Framework vulnerabilities | cvebase