Microsoft Net Framework vulnerabilities
168 known vulnerabilities affecting microsoft/net_framework.
Total CVEs
168
CISA KEV
5
actively exploited
Public exploits
24
Exploited in wild
6
Severity breakdown
CRITICAL62HIGH64MEDIUM40LOW2
Vulnerabilities
Page 6 of 9
CVE-2014-0295MEDIUMCVSS 4.3Exploitedv2.0v3.5.12014-02-12
CVE-2014-0295 [MEDIUM] CWE-264 CVE-2014-0295: VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection me
VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka "VSAVB7RT ASLR Vulnerability."
nvd
CVE-2013-3128CRITICALCVSS 9.3v3.0v3.5+3 more2013-10-09
CVE-2013-3128 [CRITICAL] CVE-2013-3128: The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType F
nvd
CVE-2013-3860HIGHCVSS 7.8v2.0v3.5+3 more2013-10-09
CVE-2013-3860 [HIGH] CWE-20 CVE-2013-3860: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD duri
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML document, aka "Entity Expansion Vulnerability."
nvd
CVE-2013-3861HIGHCVSS 7.8v2.0v3.5+3 more2013-10-09
CVE-2013-3861 [HIGH] CWE-20 CVE-2013-3861: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerability."
nvd
CVE-2013-3132CRITICALCVSS 9.3v1.0v1.1+5 more2013-07-10
CVE-2013-3132 [CRITICAL] CWE-94 CVE-2013-3132: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check t
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
nvd
CVE-2013-3131CRITICALCVSS 9.3v2.0v3.5+3 more2013-07-10
CVE-2013-3131 [CRITICAL] CWE-94 CVE-2013-3131: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation V
nvd
CVE-2013-3134CRITICALCVSS 9.3v2.0v3.5+3 more2013-07-10
CVE-2013-3134 [CRITICAL] CWE-94 CVE-2013-3134: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
nvd
CVE-2013-3171CRITICALCVSS 9.3v2.0v3.5+3 more2013-07-10
CVE-2013-3171 [CRITICAL] CWE-94 CVE-2013-3171: The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5
The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relations
nvd
CVE-2013-3133CRITICALCVSS 9.3v2.0v3.5+3 more2013-07-10
CVE-2013-3133 [CRITICAL] CWE-94 CVE-2013-3133: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
nvd
CVE-2013-3129HIGHCVSS 7.8v3.0v3.5+3 more2013-07-10
CVE-2013-3129 [HIGH] CWE-94 CVE-2013-3129: Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.s
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003
nvd
CVE-2013-1337HIGHCVSS 7.5v4.52013-05-15
CVE-2013-1337 [HIGH] CWE-287 CVE-2013-1337: Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communi
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."
nvd
CVE-2013-1336MEDIUMCVSS 5.0v2.0v3.5+3 more2013-05-15
CVE-2013-1336 [MEDIUM] CWE-20 CVE-2013-1336: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does n
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
nvd
CVE-2013-0073CRITICALCVSS 10.0v3.5v3.5.1+3 more2013-02-13
CVE-2013-0073 [CRITICAL] CWE-264 CVE-2013-0073: The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Win
nvd
CVE-2013-0004CRITICALCVSS 9.3v1.0v1.1+5 more2013-01-09
CVE-2013-0004 [CRITICAL] CWE-20 CVE-2013-0004: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properl
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
nvd
CVE-2013-0002CRITICALCVSS 9.3v1.0v1.1+5 more2013-01-09
CVE-2013-0002 [CRITICAL] CWE-119 CVE-2013-0002: Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memor
nvd
CVE-2013-0003CRITICALCVSS 9.3v2.0v4.0+3 more2013-01-09
CVE-2013-0003 [CRITICAL] CWE-119 CVE-2013-0003: Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET
Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory
nvd
CVE-2013-0005HIGHCVSS 7.8v3.5v3.5.1+1 more2013-01-09
CVE-2013-0005 [HIGH] CWE-20 CVE-2013-0005: The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Fram
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Serv
nvd
CVE-2013-0001MEDIUMCVSS 4.3v1.0v1.1+5 more2013-01-09
CVE-2013-0001 [MEDIUM] CWE-200 CVE-2013-0001: The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unma
nvd
CVE-2012-1895CRITICALCVSS 9.3v1.0v1.1+3 more2012-11-14
CVE-2012-1895 [CRITICAL] CWE-264 CVE-2012-1895: The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 do
The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
nvd
CVE-2012-4777CRITICALCVSS 9.3v4.0v4.52012-11-14
CVE-2012-4777 [CRITICAL] CWE-264 CVE-2012-4777: The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5
The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "WPF Reflection Optimization Vulnerability."
nvd