Microsoft Net Framework vulnerabilities
185 known vulnerabilities affecting microsoft/net_framework.
Total CVEs
185
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH79MEDIUM41LOW2
Vulnerabilities
Page 5 of 10
CVE-2009-0090P3CRITICALCVSS 9.3v1.1v2.0+2 more2009-10-14
CVE-2009-0090 [CRITICAL] CWE-264 CVE-2009-0090: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable co
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsof
nvd
CVE-2007-0043P3CRITICALCVSS 9.3v1.0v1.1+1 more2007-07-10
CVE-2007-0043 [CRITICAL] CWE-119 CVE-2007-0043: The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 20
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
nvd
CVE-2024-0057P3CRITICALCVSS 9.8≥ 4.8, < 4.8.04690.02≥ 4.8, < 4.8.04690.01+8 more2024-01-09
CVE-2024-0057 [CRITICAL] CWE-20 CVE-2024-0057: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
nvd
CVE-2009-2528P3CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2528 [CRITICAL] CWE-94 CVE-2009-2528: GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Ta
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
nvd
CVE-2012-0014P3HIGHCVSS 7.8v2.0v3.5.1+1 more2012-02-14
CVE-2012-0014 [HIGH] CWE-94 CVE-2012-0014: Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properl
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4
nvd
CVE-2016-7270P3HIGHCVSS 7.5v4.6.22016-12-20
CVE-2016-7270 [HIGH] CWE-310 CVE-2016-7270: The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied k
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
nvd
CVE-2015-2480P3CRITICALCVSS 9.3v4.62015-08-15
CVE-2015-2480 [CRITICAL] CVE-2015-2480: The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at opt
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execute arbitrary code via a crafted .NET application, aka "RyuJIT Optimization Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2479 and CVE-2015-2481.
nvd
CVE-2015-2481P3CRITICALCVSS 9.3v4.62015-08-15
CVE-2015-2481 [CRITICAL] CVE-2015-2481: The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at opt
The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execute arbitrary code via a crafted .NET application, aka "RyuJIT Optimization Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2479 and CVE-2015-2480.
nvd
CVE-2025-21176P3HIGHCVSS 8.8v4.6v4.6.2+6 more2025-01-14
CVE-2025-21176 [HIGH] CWE-126 CVE-2025-21176: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2011-1253P3CRITICALCVSS 9.3v1.0v1.1+3 more2011-10-12
CVE-2011-1253 [CRITICAL] CWE-264 CVE-2011-1253: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silv
nvd
CVE-2015-6096P3MEDIUMCVSS 4.3v2.0v3.5+6 more2015-11-11
CVE-2015-6096 [MEDIUM] CWE-200 CVE-2015-6096: The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 al
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
nvd
CVE-2024-0056P3HIGHCVSS 8.7≥ 4.8, < 4.8.04690.02≥ 4.8, < 4.8.04690.01+7 more2024-01-09
CVE-2024-0056 [HIGH] CWE-319 CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnera
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
nvd
CVE-2016-0148P3HIGHCVSS 7.8v4.6v4.6.12016-04-12
CVE-2016-0148 [HIGH] CWE-264 CVE-2016-0148: Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."
nvd
CVE-2016-0047P3HIGHCVSS 7.5v2.0v3.5+4 more2016-02-10
CVE-2016-0047 [HIGH] CWE-200 CVE-2016-0047: WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attack
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability."
nvd
CVE-2019-1006P3HIGHCVSS 7.5v2.0v3.0+10 more2019-07-15
CVE-2019-1006 [HIGH] CWE-295 CVE-2019-1006: An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
nvd
CVE-2013-0005P3HIGHCVSS 7.8v3.5v3.5.1+1 more2013-01-09
CVE-2013-0005 [HIGH] CWE-20 CVE-2013-0005: The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Fram
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Serv
nvd
CVE-2013-3860P3HIGHCVSS 7.8v2.0v3.5+3 more2013-10-09
CVE-2013-3860 [HIGH] CWE-20 CVE-2013-3860: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD duri
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML document, aka "Entity Expansion Vulnerability."
nvd
CVE-2016-0033P3HIGHCVSS 7.5v2.0v3.5+4 more2016-02-10
CVE-2016-0033 [HIGH] CWE-94 CVE-2016-0033: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compi
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka ".NET Framework Stack Overflow Denial of Service Vulnerability."
nvd
CVE-2026-33116P3HIGHCVSS 7.5v3.5v4.7.2+5 more2026-04-14
CVE-2026-33116 [HIGH] CWE-20 CVE-2026-33116: Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-23666P3HIGHCVSS 7.5v3.5v4.7.2+5 more2026-04-14
CVE-2026-23666 [HIGH] CWE-755 CVE-2026-23666: Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a n
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd