Microsoft Net Framework vulnerabilities
185 known vulnerabilities affecting microsoft/net_framework.
Total CVEs
185
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH79MEDIUM41LOW2
Vulnerabilities
Page 3 of 10
CVE-2013-3134P2CRITICALCVSS 9.3v2.0v3.5+3 more2013-07-10
CVE-2013-3134 [CRITICAL] CWE-94 CVE-2013-3134: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
nvd
CVE-2015-2504P3CRITICALCVSS 9.3v2.0v3.5+6 more2015-09-09
CVE-2015-2504 [CRITICAL] CWE-119 CVE-2015-2504: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts object
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array copy, which allows remote attackers to (1) execute arbitrary code via a crafted XAML browser application (XBAP) or (2) bypass Code Access Security restrictions via a crafted .NET Framework application, aka ".NET Elevation
nvd
CVE-2009-2500P2CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2500 [CRITICAL] CWE-189 CVE-2009-2500: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP
nvd
CVE-2012-1895P3CRITICALCVSS 9.3v1.0v1.1+3 more2012-11-14
CVE-2012-1895 [CRITICAL] CWE-264 CVE-2012-1895: The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 do
The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
nvd
CVE-2012-0161P2CRITICALCVSS 9.3v1.0v1.1+5 more2012-05-09
CVE-2012-0161 [CRITICAL] CWE-20 CVE-2012-0161: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework applicati
nvd
CVE-2013-3171P3CRITICALCVSS 9.3v2.0v3.5+3 more2013-07-10
CVE-2013-3171 [CRITICAL] CWE-94 CVE-2013-3171: The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5
The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relations
nvd
CVE-2012-4777P3CRITICALCVSS 9.3v4.0v4.52012-11-14
CVE-2012-4777 [CRITICAL] CWE-264 CVE-2012-4777: The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5
The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "WPF Reflection Optimization Vulnerability."
nvd
CVE-2009-2503P3CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2503 [CRITICAL] CWE-94 CVE-2009-2503: GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office X
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold
nvd
CVE-2013-1337P3HIGHCVSS 7.5v4.52013-05-15
CVE-2013-1337 [HIGH] CWE-287 CVE-2013-1337: Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communi
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."
nvd
CVE-2013-3132P3CRITICALCVSS 9.3v1.0v1.1+5 more2013-07-10
CVE-2013-3132 [CRITICAL] CWE-94 CVE-2013-3132: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check t
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
nvd
CVE-2019-0613P3HIGHCVSS 8.8v2.0v3.0+9 more2019-03-05
CVE-2019-0613 [HIGH] CWE-119 CVE-2019-0613: A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the s
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework and Visual Studio Remote Code Execution Vulnerability'.
nvd
CVE-2013-3861P3HIGHCVSS 7.8v2.0v3.5+3 more2013-10-09
CVE-2013-3861 [HIGH] CWE-20 CVE-2013-3861: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerability."
nvd
CVE-2010-1898P3CRITICALCVSS 9.3v2.0v3.5+1 more2010-08-11
CVE-2010-1898 [CRITICAL] CWE-94 CVE-2010-1898: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted X
nvd
CVE-2012-4776P3CRITICALCVSS 9.3v2.0v3.5.1+3 more2012-11-14
CVE-2012-4776 [CRITICAL] CWE-20 CVE-2012-4776: The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4
The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka
nvd
CVE-2013-0003P3CRITICALCVSS 9.3v2.0v4.0+3 more2013-01-09
CVE-2013-0003 [CRITICAL] CWE-119 CVE-2013-0003: Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET
Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory
nvd
CVE-2010-3958P3CRITICALCVSS 9.3v4.0v3.5.1+2 more2011-04-13
CVE-2010-3958 [CRITICAL] CWE-20 CVE-2010-3958: The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption V
nvd
CVE-2015-1673P3CRITICALCVSS 9.3v1.1v2.0+6 more2015-05-13
CVE-2015-1673 [CRITICAL] CWE-264 CVE-2015-1673: The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1,
The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbitrary code via a crafted partial-trust application, aka "Windows Forms Elevation of Privilege Vulnerability."
nvd
CVE-2020-0605P3HIGHCVSS 8.8v3.0v3.5+9 more2020-01-14
CVE-2020-0605 [HIGH] CWE-20 CVE-2020-0605: A remote code execution vulnerability exists in .NET software when the software fails to check the s
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0606.
nvd
CVE-2020-0606P3HIGHCVSS 8.8v3.0v3.5+9 more2020-01-14
CVE-2020-0606 [HIGH] CVE-2020-0606: A remote code execution vulnerability exists in .NET software when the software fails to check the s
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0605.
nvd
CVE-2012-0162P3CRITICALCVSS 9.3v4.02012-05-09
CVE-2012-0162 [CRITICAL] CWE-119 CVE-2012-0162: Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to exec
Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Buffer Allocation Vulnerability."
nvd