cbcvebase.

Microsoft Net Framework vulnerabilities

189 known vulnerabilities affecting microsoft/net_framework.

Total CVEs
189
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH83MEDIUM41LOW2

Vulnerabilities

Page 8 of 10
CVE-2023-24895P3HIGHCVSS 7.8v4.8v4.6.2+8 more2023-06-14
CVE-2023-24895 [HIGH] CVE-2023-24895: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2019-1083P3HIGHCVSS 7.5v2.0v3.0+10 more2019-07-15
CVE-2019-1083 [HIGH] CWE-19 CVE-2019-1083: A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly han A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.
nvd
CVE-2023-24936P3HIGHCVSS 7.5v4.8v4.6.2+8 more2023-06-14
CVE-2023-24936 [HIGH] CVE-2023-24936: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2006-1300P4MEDIUMCVSS 5.0v2.02006-07-11
CVE-2006-1300 [MEDIUM] CVE-2006-1300: Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 200 Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
nvd
CVE-2018-8517P3HIGHCVSS 7.5v3.5v3.5-sp1+8 more2018-12-12
CVE-2018-8517 [HIGH] CVE-2018-8517: A denial of service vulnerability exists when .NET Framework improperly handles special web requests A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5
nvd
CVE-2024-43484P3HIGHCVSS 7.5v3.5v4.8.1+9 more2024-10-08
CVE-2024-43484 [HIGH] CWE-407 CVE-2024-43484: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-43483P3HIGHCVSS 7.5v3.5v4.8.1+9 more2024-10-08
CVE-2024-43483 [HIGH] CWE-407 CVE-2024-43483: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2018-1039P3HIGHCVSS 7.8v2.0v3.0+8 more2018-05-09
CVE-2018-1039 [HIGH] CVE-2018-1039: A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to by A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0,
nvd
CVE-2022-41089P3HIGHCVSS 7.8v3.5v4.8+10 more2022-12-13
CVE-2022-41089 [HIGH] CVE-2022-41089: .NET Framework Remote Code Execution Vulnerability .NET Framework Remote Code Execution Vulnerability
nvd
CVE-2023-29326P3HIGHCVSS 7.8v3.5.1v3.5+8 more2023-06-14
CVE-2023-29326 [HIGH] CVE-2023-29326: .NET Framework Remote Code Execution Vulnerability .NET Framework Remote Code Execution Vulnerability
nvd
CVE-2014-4072P4MEDIUMCVSS 5.0v1.1v2.0+7 more2014-09-10
CVE-2014-4072 [MEDIUM] CWE-399 CVE-2014-4072: Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not pr Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka ".NET Framework Denial of Service Vulnerability."
nvd
CVE-2019-11397P3MEDIUMCVSS 6.5v4.52019-05-14
CVE-2019-11397 [MEDIUM] CWE-22 CVE-2019-11397: GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framew GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.
nvd
CVE-2018-8202P3HIGHCVSS 7.8v2.0-sp2v3.0-sp2+9 more2018-07-11
CVE-2018-8202 [HIGH] CVE-2018-8202: An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to el An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framewo
nvd
CVE-2012-1896P3MEDIUMCVSS 5.0v2.0v3.5.12012-11-14
CVE-2012-1896 [MEDIUM] CWE-200 CVE-2012-1896: Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during constructi Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
nvd
CVE-2011-1977P4MEDIUMCVSS 4.3v4.02011-08-10
CVE-2011-1977 [MEDIUM] CWE-200 CVE-2011-1977: The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Frame The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability."
nvd
CVE-2013-1336P3MEDIUMCVSS 5.0v2.0v3.5+3 more2013-05-15
CVE-2013-1336 [MEDIUM] CWE-20 CVE-2013-1336: The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does n The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
nvd
CVE-2024-38081P3HIGHCVSS 7.3v4.6.2v4.7+8 more2024-07-09
CVE-2024-38081 [HIGH] CWE-59 CVE-2024-38081: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-29331P3HIGHCVSS 7.5v4.8v4.6.2+8 more2023-06-14
CVE-2023-29331 [HIGH] CWE-400 CVE-2023-29331: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
nvd
CVE-2023-32030P3HIGHCVSS 7.5v4.8v4.6.2+8 more2023-06-14
CVE-2023-32030 [HIGH] CVE-2023-32030: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2011-1978P4MEDIUMCVSS 4.3v4.0v3.5.1+1 more2011-08-10
CVE-2011-1978 [MEDIUM] CWE-200 CVE-2011-1978: Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets tru Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application,
nvd
Microsoft Net Framework vulnerabilities | cvebase