cbcvebase.

Microsoft Visual Studio Net vulnerabilities

27 known vulnerabilities affecting microsoft/visual_studio_net.

Total CVEs
27
CISA KEV
0
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL13HIGH11MEDIUM3

Vulnerabilities

Page 2 of 2
CVE-2007-1201P3CRITICALCVSS 9.3v2002v20032008-03-11
CVE-2007-1201 [CRITICAL] CWE-94 CVE-2007-1201: Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
nvd
CVE-2009-2528P3CRITICALCVSS 9.3v2003v20052009-10-14
CVE-2009-2528 [CRITICAL] CWE-94 CVE-2009-2528: GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Ta GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
nvd
CVE-2008-4252P3HIGHCVSS 8.5v2002v20032008-12-10
CVE-2008-4252 [HIGH] CWE-264 CVE-2008-4252: The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruptio
nvd
CVE-2006-0187P4MEDIUMCVSS 5.1PoCv20052006-01-12
CVE-2006-0187 [MEDIUM] CVE-2006-0187: By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defi By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
nvd
CVE-2009-2495P3MEDIUMCVSS 6.5v20032009-07-29
CVE-2009-2495 [MEDIUM] CWE-200 CVE-2009-2495: The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 a The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that tri
nvd
CVE-2007-1512P3CRITICALCVSS 10.0v2002v20032007-03-20
CVE-2007-1512 [CRITICAL] CVE-2007-1512: Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Wind Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in
nvd
CVE-2010-3190P3HIGHCVSS 7.8v20032010-08-31
CVE-2010-3190 [HIGH] CWE-426 CVE-2010-3190: Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Vis Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current
nvd
Microsoft Visual Studio Net vulnerabilities | cvebase