Microsoft Net Framework vulnerabilities

165 known vulnerabilities affecting microsoft/net_framework.

Total CVEs
165
CISA KEV
5
actively exploited
Public exploits
22
Exploited in wild
6
Severity breakdown
CRITICAL62HIGH62MEDIUM39LOW2

Vulnerabilities

Page 8 of 9
CVE-2009-2500CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2500 [CRITICAL] CWE-189 CVE-2009-2500: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3 Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP
nvd
CVE-2009-2504CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2504 [CRITICAL] CWE-189 CVE-2009-2504: Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Fra Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word
nvd
CVE-2009-2503CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2503 [CRITICAL] CWE-94 CVE-2009-2503: GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office X GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold
nvd
CVE-2009-2497CRITICALCVSS 9.3v2.0v1.1+2 more2009-10-14
CVE-2009-2497 [CRITICAL] CWE-94 CVE-2009-2497: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a cra
nvd
CVE-2009-3126CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-3126 [CRITICAL] CWE-189 CVE-2009-3126: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3 Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP
nvd
CVE-2009-2528CRITICALCVSS 9.3v1.1v2.02009-10-14
CVE-2009-2528 [CRITICAL] CWE-94 CVE-2009-2528: GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Ta GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
nvd
CVE-2009-0090CRITICALCVSS 9.3v1.1v2.0+2 more2009-10-14
CVE-2009-0090 [CRITICAL] CWE-264 CVE-2009-0090: Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable co Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsof
nvd
CVE-2009-2502HIGHCVSS 8.1v1.1v2.02009-10-14
CVE-2009-2502 [HIGH] CWE-119 CVE-2009-2502: Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, an
nvd
CVE-2009-1536LOWCVSS 2.6v2.0v3.52009-08-12
CVE-2009-1536 [LOW] CWE-20 CVE-2009-1536: ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in in ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
nvd
CVE-2008-5100CRITICALCVSS 10.0v2.0.507272008-11-17
CVE-2008-5100 [CRITICAL] CWE-310 CVE-2008-5100: The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital sign The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSR
nvd
CVE-2008-3842MEDIUMCVSS 4.3v2.0v1.1+1 more2008-08-27
CVE-2008-3842 [MEDIUM] CWE-79 CVE-2008-3842: Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "</" (less-than slash) sequence.
nvd
CVE-2008-3843MEDIUMCVSS 4.3v1.0v1.1+1 more2008-08-27
CVE-2008-3843 [MEDIUM] CWE-79 CVE-2008-3843: Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STY
nvd
CVE-2007-0041CRITICALCVSS 9.3v1.0v1.1+1 more2007-07-10
CVE-2007-0041 [CRITICAL] CWE-119 CVE-2007-0041: The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 200 The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
nvd
CVE-2007-0043CRITICALCVSS 9.3v1.0v1.1+1 more2007-07-10
CVE-2007-0043 [CRITICAL] CWE-119 CVE-2007-0043: The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 20 The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
nvd
CVE-2007-0042HIGHCVSS 7.8PoCv1.0v1.1+1 more2007-07-10
CVE-2007-0042 [HIGH] CWE-200 CVE-2007-0042: Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, X Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a
nvd
CVE-2006-7192MEDIUMCVSS 4.3v2.02007-04-10
CVE-2006-7192 [MEDIUM] CVE-2006-7192: Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
nvd
CVE-2006-3436MEDIUMCVSS 4.3v2.02006-10-10
CVE-2006-3436 [MEDIUM] CVE-2006-3436: Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
nvd
CVE-2006-1300MEDIUMCVSS 5.0v2.02006-07-11
CVE-2006-1300 [MEDIUM] CVE-2006-1300: Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 200 Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
nvd
CVE-2006-1511MEDIUMCVSS 5.1v1.0v1.12006-03-30
CVE-2006-1511 [MEDIUM] CVE-2006-1511: Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user- Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
nvd
CVE-2006-1510MEDIUMCVSS 4.0PoCv1.0v1.12006-03-30
CVE-2006-1510 [MEDIUM] CVE-2006-1510: Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by t Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.
nvd