cbcvebase.

Microsoft Net Framework vulnerabilities

168 known vulnerabilities affecting microsoft/net_framework.

Total CVEs
168
CISA KEV
5
actively exploited
Public exploits
24
Exploited in wild
6
Severity breakdown
CRITICAL62HIGH64MEDIUM40LOW2

Vulnerabilities

Page 9 of 9
CVE-2006-1300MEDIUMCVSS 5.0v2.02006-07-11
CVE-2006-1300 [MEDIUM] CVE-2006-1300: Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 200 Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
nvd
CVE-2006-1511MEDIUMCVSS 5.1v1.0v1.12006-03-30
CVE-2006-1511 [MEDIUM] CVE-2006-1511: Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user- Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
nvd
CVE-2006-1510MEDIUMCVSS 4.0PoCv1.0v1.12006-03-30
CVE-2006-1510 [MEDIUM] CVE-2006-1510: Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by t Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.
nvd
CVE-2005-2127HIGHCVSS 7.5PoCv1.12005-08-19
CVE-2005-2127 [HIGH] CWE-119 CVE-2005-2127: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (a Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.
nvd
CVE-2005-0509MEDIUMCVSS 4.3v1.0v1.12005-03-14
CVE-2005-0509 [MEDIUM] CVE-2005-0509: Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Ne Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
nvd
CVE-2004-0200CRITICALCVSS 9.3PoCv1.02004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2002-0369CRITICALCVSS 10.0v1.02002-07-26
CVE-2002-0369 [CRITICAL] CVE-2002-0369: Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (rest Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode.
nvd
CVE-2002-0409MEDIUMCVSS 5.0v1.02002-07-26
CVE-2002-0409 [MEDIUM] CVE-2002-0409: orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated o orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
nvd