Microsoft Net Framework vulnerabilities
185 known vulnerabilities affecting microsoft/net_framework.
Total CVEs
185
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH79MEDIUM41LOW2
Vulnerabilities
Page 8 of 10
CVE-2023-29326P3HIGHCVSS 7.8v3.5.1v3.5+8 more2023-06-14
CVE-2023-29326 [HIGH] CVE-2023-29326: .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
nvd
CVE-2006-1300P4MEDIUMCVSS 5.0v2.02006-07-11
CVE-2006-1300 [MEDIUM] CVE-2006-1300: Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 200
Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
nvd
CVE-2018-8517P3HIGHCVSS 7.5v3.5v3.5-sp1+8 more2018-12-12
CVE-2018-8517 [HIGH] CVE-2018-8517: A denial of service vulnerability exists when .NET Framework improperly handles special web requests
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5
nvd
CVE-2018-1039P3HIGHCVSS 7.8v2.0v3.0+8 more2018-05-09
CVE-2018-1039 [HIGH] CVE-2018-1039: A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to by
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0,
nvd
CVE-2022-41089P3HIGHCVSS 7.8v3.5v4.8+10 more2022-12-13
CVE-2022-41089 [HIGH] CVE-2022-41089: .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
nvd
CVE-2014-4072P4MEDIUMCVSS 5.0v1.1v2.0+7 more2014-09-10
CVE-2014-4072 [MEDIUM] CWE-399 CVE-2014-4072: Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not pr
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka ".NET Framework Denial of Service Vulnerability."
nvd
CVE-2019-11397P3MEDIUMCVSS 6.5v4.52019-05-14
CVE-2019-11397 [MEDIUM] CWE-22 CVE-2019-11397: GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framew
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.
nvd
CVE-2024-43484P3HIGHCVSS 7.5v3.5v4.8.1+9 more2024-10-08
CVE-2024-43484 [HIGH] CWE-407 CVE-2024-43484: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-43483P3HIGHCVSS 7.5v3.5v4.8.1+9 more2024-10-08
CVE-2024-43483 [HIGH] CWE-407 CVE-2024-43483: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2018-8202P3HIGHCVSS 7.8v2.0-sp2v3.0-sp2+9 more2018-07-11
CVE-2018-8202 [HIGH] CVE-2018-8202: An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to el
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framewo
nvd
CVE-2012-1896P3MEDIUMCVSS 5.0v2.0v3.5.12012-11-14
CVE-2012-1896 [MEDIUM] CWE-200 CVE-2012-1896: Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during constructi
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
nvd
CVE-2023-29331P3HIGHCVSS 7.5v4.8v4.6.2+8 more2023-06-14
CVE-2023-29331 [HIGH] CWE-400 CVE-2023-29331: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2011-1977P4MEDIUMCVSS 4.3v4.02011-08-10
CVE-2011-1977 [MEDIUM] CWE-200 CVE-2011-1977: The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Frame
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability."
nvd
CVE-2013-1336P3MEDIUMCVSS 5.0v2.0v3.5+3 more2013-05-15
CVE-2013-1336 [MEDIUM] CWE-20 CVE-2013-1336: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does n
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
nvd
CVE-2024-38081P3HIGHCVSS 7.3v4.6.2v4.7+8 more2024-07-09
CVE-2024-38081 [HIGH] CWE-59 CVE-2024-38081: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-32030P3HIGHCVSS 7.5v4.8v4.6.2+8 more2023-06-14
CVE-2023-32030 [HIGH] CVE-2023-32030: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2011-1978P4MEDIUMCVSS 4.3v4.0v3.5.1+1 more2011-08-10
CVE-2011-1978 [MEDIUM] CWE-200 CVE-2011-1978: Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets tru
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application,
nvd
CVE-2016-0149P3MEDIUMCVSS 5.9v2.0v3.0+5 more2016-05-11
CVE-2016-0149 [MEDIUM] CWE-200 CVE-2016-0149: Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middl
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure Vulnerability."
nvd
CVE-2026-32226P4MEDIUMCVSS 5.9v3.5v4.7.2+2 more2026-04-14
CVE-2026-32226 [MEDIUM] CWE-362 CVE-2026-32226: Concurrent execution using shared resource with improper synchronization ('race condition') in .NET
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2015-2526P4MEDIUMCVSS 5.0v4.5v4.5.1+2 more2015-09-09
CVE-2015-2526 [MEDIUM] CWE-17 CVE-2015-2526: Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of ser
Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC Denial of Service Vulnerability."
nvd