Microsoft Net Framework vulnerabilities
185 known vulnerabilities affecting microsoft/net_framework.
Total CVEs
185
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH79MEDIUM41LOW2
Vulnerabilities
Page 6 of 10
CVE-2026-50652P3HIGHCVSS 7.5v3.5v4.8.1+5 more2026-07-14
CVE-2026-50652 [HIGH] CWE-502 CVE-2026-50652: Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50355P3HIGHCVSS 7.5v4.8.1v4.8+5 more2026-07-14
CVE-2026-50355 [HIGH] CWE-121 CVE-2026-50355: Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50368P3HIGHCVSS 7.5v4.8.1v4.8+5 more2026-07-14
CVE-2026-50368 [HIGH] CWE-121 CVE-2026-50368: Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50411P3HIGHCVSS 7.5v4.8.1v4.8+5 more2026-07-14
CVE-2026-50411 [HIGH] CWE-121 CVE-2026-50411: Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized a
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2008-5100P3CRITICALCVSS 10.0v2.0.507272008-11-17
CVE-2008-5100 [CRITICAL] CWE-310 CVE-2008-5100: The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital sign
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSR
nvd
CVE-2026-50527P3HIGHCVSS 7.5v4.8v4.6.2+5 more2026-07-14
CVE-2026-50527 [HIGH] CWE-121 CVE-2026-50527: Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2019-0545P3HIGHCVSS 7.5v2.0-sp2v3.0-sp2+9 more2019-01-08
CVE-2019-0545 [HIGH] CWE-200 CVE-2019-0545: An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassin
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Frame
nvd
CVE-2018-8360P3HIGHCVSS 7.5v2.0-sp2v3.0-sp2+9 more2018-08-15
CVE-2018-8360 [HIGH] CWE-200 CVE-2018-8360: An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attac
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.0, Microsoft .NET Framework
nvd
CVE-2026-50649P3HIGHCVSS 7.8v4.8.1v4.8+5 more2026-07-14
CVE-2026-50649 [HIGH] CWE-502 CVE-2026-50649: Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-47302P3HIGHCVSS 7.5v4.8v4.6.2+5 more2026-07-14
CVE-2026-47302 [HIGH] CWE-770 CVE-2026-47302: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2017-0248P3HIGHCVSS 7.5v2.0v3.5+6 more2017-05-12
CVE-2017-0248 [HIGH] CWE-295 CVE-2017-0248: Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypa
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
nvd
CVE-2006-1510P4MEDIUMCVSS 4.0PoCv1.0v1.12006-03-30
CVE-2006-1510 [MEDIUM] CVE-2006-1510: Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by t
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.
nvd
CVE-2026-50646P3HIGHCVSS 7.8v4.8v4.6.2+5 more2026-07-14
CVE-2026-50646 [HIGH] CWE-502 CVE-2026-50646: Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50648P3HIGHCVSS 7.5v4.8v4.6.2+5 more2026-07-14
CVE-2026-50648 [HIGH] CWE-770 CVE-2026-50648: Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50525P3HIGHCVSS 7.5v4.8.1v4.8+5 more2026-07-14
CVE-2026-50525 [HIGH] CWE-770 CVE-2026-50525: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32177P3HIGHCVSS 7.3v4.8v4.6.2+5 more2026-05-12
CVE-2026-32177 [HIGH] CWE-20 CVE-2026-32177: Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-50647P3HIGHCVSS 7.5v4.8.1v4.8+5 more2026-07-14
CVE-2026-50647 [HIGH] CWE-835 CVE-2026-50647: Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD F
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50650P3HIGHCVSS 7.8v4.8v4.6.2+5 more2026-07-14
CVE-2026-50650 [HIGH] CWE-94 CVE-2026-50650: Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized a
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-50653P3HIGHCVSS 7.5v3.5v4.8.1+5 more2026-07-14
CVE-2026-50653 [HIGH] CWE-400 CVE-2026-50653: Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthori
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
nvd
CVE-2020-1108P3HIGHCVSS 7.5v2.0v3.0+10 more2020-05-21
CVE-2020-1108 [HIGH] CVE-2020-1108: A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web req
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
nvd