Microsoft Net Framework vulnerabilities
185 known vulnerabilities affecting microsoft/net_framework.
Total CVEs
185
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH79MEDIUM41LOW2
Vulnerabilities
Page 4 of 10
CVE-2009-2504P3CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2504 [CRITICAL] CWE-189 CVE-2009-2504: Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Fra
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word
nvd
CVE-2013-3133P3CRITICALCVSS 9.3v2.0v3.5+3 more2013-07-10
CVE-2013-3133 [CRITICAL] CWE-94 CVE-2013-3133: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
nvd
CVE-2023-36049P3CRITICALCVSS 9.8v2.0v3.0+8 more2023-11-14
CVE-2023-36049 [CRITICAL] CWE-20 CVE-2023-36049: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2018-8260P3HIGHCVSS 8.8v4.7.2v4.7.2 Developer Pack2018-07-11
CVE-2018-8260 [HIGH] CWE-20 CVE-2018-8260: A Remote Code Execution vulnerability exists in .NET software when the software fails to check the s
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.
nvd
CVE-2007-0041P3CRITICALCVSS 9.3v1.0v1.1+1 more2007-07-10
CVE-2007-0041 [CRITICAL] CWE-119 CVE-2007-0041: The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 200
The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
nvd
CVE-2012-0015P3CRITICALCVSS 9.3v2.0v3.5.12012-02-14
CVE-2012-0015 [CRITICAL] CWE-94 CVE-2012-0015: Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."
nvd
CVE-2013-3129P3HIGHCVSS 7.8v3.0v3.5+3 more2013-07-10
CVE-2013-3129 [HIGH] CWE-94 CVE-2013-3129: Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.s
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003
nvd
CVE-2011-0664P3CRITICALCVSS 9.3v4.0v3.5.1+2 more2011-06-16
CVE-2011-0664 [CRITICAL] CWE-20 CVE-2011-0664: Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before
Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted
nvd
CVE-2013-0004P3CRITICALCVSS 9.3v1.0v1.1+5 more2013-01-09
CVE-2013-0004 [CRITICAL] CWE-20 CVE-2013-0004: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properl
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
nvd
CVE-2014-4121P3CRITICALCVSS 10.0v2.0v3.5+5 more2014-10-15
CVE-2014-4121 [CRITICAL] CWE-399 CVE-2014-4121: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse inter
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."
nvd
CVE-2012-1855P3CRITICALCVSS 9.3v2.0v3.5.1+1 more2012-06-12
CVE-2012-1855 [CRITICAL] CWE-94 CVE-2012-1855: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers,
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."
nvd
CVE-2016-3255P3HIGHCVSS 7.5v2.0v3.5+4 more2016-07-13
CVE-2016-3255 [HIGH] CWE-200 CVE-2016-3255: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
nvd
CVE-2009-0091P3CRITICALCVSS 9.3v1.1v2.0+2 more2009-10-14
CVE-2009-0091 [CRITICAL] CWE-94 CVE-2009-0091: Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality con
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Ty
nvd
CVE-2010-3228P3CRITICALCVSS 9.3v4.02010-10-13
CVE-2010-3228 [CRITICAL] CWE-94 CVE-2010-3228: The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optim
The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote attackers to execute arbitrary code via a crafted .NET application that triggers memory corruption, aka ".NET Framework x64 JIT Compiler Vulnerability."
nvd
CVE-2013-0002P3CRITICALCVSS 9.3v1.0v1.1+5 more2013-01-09
CVE-2013-0002 [CRITICAL] CWE-119 CVE-2013-0002: Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memor
nvd
CVE-2009-2502P3HIGHCVSS 8.1v1.1v2.02009-10-14
CVE-2009-2502 [HIGH] CWE-119 CVE-2009-2502: Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3,
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, an
nvd
CVE-2015-2479P3CRITICALCVSS 9.3v4.62015-08-15
CVE-2015-2479 [CRITICAL] CWE-264 CVE-2015-2479: The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at opt
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execute arbitrary code via a crafted .NET application, aka "RyuJIT Optimization Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2480 and CVE-2015-2481.
nvd
CVE-2019-1113P3HIGHCVSS 8.8v2.0v3.0+10 more2019-07-15
CVE-2019-1113 [HIGH] CWE-20 CVE-2019-1113: A remote code execution vulnerability exists in .NET software when the software fails to check the s
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.
nvd
CVE-2026-47304P3CRITICALCVSS 9.8v4.8.1v4.8+5 more2026-07-14
CVE-2026-47304 [CRITICAL] CWE-345 CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2009-2497P3CRITICALCVSS 9.3v2.0v1.1+2 more2009-10-14
CVE-2009-2497 [CRITICAL] CWE-94 CVE-2009-2497: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a cra
nvd