cbcvebase.

Microsoft Net Framework vulnerabilities

185 known vulnerabilities affecting microsoft/net_framework.

Total CVEs
185
CISA KEV
5
actively exploited
Public exploits
25
Exploited in wild
14
Severity breakdown
CRITICAL63HIGH79MEDIUM41LOW2

Vulnerabilities

Page 9 of 10
CVE-2012-2519P4HIGHCVSS 7.9v1.0v1.1+4 more2012-11-14
CVE-2012-2519 [HIGH] CVE-2012-2519: Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 S Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
nvd
CVE-2019-0657P4MEDIUMCVSS 5.9v2.0v3.0+9 more2019-03-05
CVE-2019-0657 [MEDIUM] CWE-20 CVE-2019-0657: A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
nvd
CVE-2025-55248P4MEDIUMCVSS 5.7v4.6.2v4.7+7 more2025-10-14
CVE-2025-55248 [MEDIUM] CWE-326 CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
nvd
CVE-2006-3436P4MEDIUMCVSS 4.3v2.02006-10-10
CVE-2006-3436 [MEDIUM] CVE-2006-3436: Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
nvd
CVE-2015-1672P4MEDIUMCVSS 5.0v2.0v3.5+5 more2015-05-13
CVE-2015-1672 [MEDIUM] CWE-310 CVE-2015-1672: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to ca Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performance degradation) via crafted encrypted data in an XML document, aka ".NET XML Decryption Denial of Service Vulnerability."
nvd
CVE-2008-3843P4MEDIUMCVSS 4.3v1.0v1.1+1 more2008-08-27
CVE-2008-3843 [MEDIUM] CWE-79 CVE-2008-3843: Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STY
nvd
CVE-2012-0164P4MEDIUMCVSS 5.0v4.02012-05-09
CVE-2012-0164 [MEDIUM] CVE-2012-0164: Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka ".NET Framework Index Comparison Vulnerability."
nvd
CVE-2020-1476P4MEDIUMCVSS 5.5v2.0v3.5+9 more2020-08-17
CVE-2020-1476 [MEDIUM] CVE-2020-1476: An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an attacker would need to send a specially crafted request to an affected server. The update
nvd
CVE-2002-0409P4MEDIUMCVSS 5.0v1.02002-07-26
CVE-2002-0409 [MEDIUM] CVE-2002-0409: orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated o orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
nvd
CVE-2013-0001P4MEDIUMCVSS 4.3v1.0v1.1+5 more2013-01-09
CVE-2013-0001 [MEDIUM] CWE-200 CVE-2013-0001: The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3. The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unma
nvd
CVE-2015-6115P4MEDIUMCVSS 4.3v2.0v3.5+1 more2015-11-11
CVE-2015-6115 [MEDIUM] CWE-200 CVE-2015-6115: Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 allows remote attackers to bypass the ASLR protecti Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka ".NET ASLR Bypass."
nvd
CVE-2015-1648P4LOWCVSS 2.6v1.1v2.0+6 more2015-04-14
CVE-2015-1648 [LOW] CWE-19 CVE-2015-1648: ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka "ASP.NET Information Disclosure Vulnerability."
nvd
CVE-2015-1670P4MEDIUMCVSS 4.3v3.0v3.5+5 more2015-05-13
CVE-2015-1670 [MEDIUM] CWE-200 CVE-2015-1670: The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4. The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote attackers to obtain sensitive information from process memory via a crafted OpenType font on a web site, aka "OpenType Font Parsing Vulnerability."
nvd
CVE-2008-3842P4MEDIUMCVSS 4.3v2.0v1.1+1 more2008-08-27
CVE-2008-3842 [MEDIUM] CWE-79 CVE-2008-3842: Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "</" (less-than slash) sequence.
nvd
CVE-2014-4062P4MEDIUMCVSS 4.3v1.1v2.0+3 more2014-08-12
CVE-2014-4062 [MEDIUM] CWE-264 CVE-2014-4062: Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, and 3.5.1 does not properly implement the A Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, and 3.5.1 does not properly implement the ASLR protection mechanism, which allows remote attackers to obtain sensitive address information via a crafted web site, aka ".NET ASLR Vulnerability."
nvd
CVE-2014-4122P4MEDIUMCVSS 4.3v2.0v3.5+1 more2014-10-15
CVE-2014-4122 [MEDIUM] CWE-264 CVE-2014-4122: Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows r Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location, aka ".NET ASLR Vulnerability."
nvd
CVE-2020-16937P4MEDIUMCVSS 5.5v2.0v3.5+9 more2020-10-16
CVE-2020-16937 [MEDIUM] CVE-2020-16937: <p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory. To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application. The update addresses the vulne
nvd
CVE-2019-1142P4MEDIUMCVSS 5.5v3.5v4.7.2+7 more2019-09-11
CVE-2019-1142 [MEDIUM] CWE-22 CVE-2019-1142: An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2006-7192P4MEDIUMCVSS 4.3v2.02007-04-10
CVE-2006-7192 [MEDIUM] CVE-2006-7192: Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
nvd
CVE-2022-41064P4MEDIUMCVSS 5.8v4.8v4.8.1+4 more2022-11-09
CVE-2022-41064 [MEDIUM] CVE-2022-41064: .NET Framework Information Disclosure Vulnerability .NET Framework Information Disclosure Vulnerability
nvd