.net Framework
by Microsoft
CVEs (207)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-0160 | Hig | 0.55 | 7.8 | 0.18 | Apr 12, 2017 | Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability." | ||
| CVE-2011-1271 | Hig | 0.55 | 7.7 | 0.20 | May 10, 2011 | The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently… | ||
| CVE-2009-2502 | Hig | 0.54 | 8.1 | 0.22 | Oct 14, 2009 | Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003… | ||
| CVE-2026-47304 | Hig | 0.53 | 8.1 | 0.00 | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2013-3129 | Hig | 0.53 | 7.8 | 0.32 | Jul 10, 2013 | Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,… | ||
| CVE-2012-0014 | Hig | 0.53 | 7.8 | 0.28 | Feb 14, 2012 | Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a… | ||
| CVE-2024-0057 | Cri | 0.52 | 9.1 | 0.03 | Jan 9, 2024 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | ||
| CVE-2016-0148 | Hig | 0.52 | 7.8 | 0.14 | Apr 12, 2016 | Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability." | ||
| CVE-2026-65810 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2023-36796 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36794 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36793 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36792 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36788 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | .NET Framework Remote Code Execution Vulnerability | ||
| CVE-2023-29326 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | .NET Framework Remote Code Execution Vulnerability | ||
| CVE-2023-24897 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-24895 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-21808 | Hig | 0.51 | 7.8 | 0.01 | Feb 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2022-26929 | Hig | 0.51 | 7.8 | 0.01 | Sep 13, 2022 | .NET Framework Remote Code Execution Vulnerability | ||
| CVE-2020-1046 | Hig | 0.51 | 7.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially… |
- risk 0.55cvss 7.8epss 0.18
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
- risk 0.55cvss 7.7epss 0.20
The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently…
- risk 0.54cvss 8.1epss 0.22
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003…
- risk 0.53cvss 8.1epss 0.00
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.53cvss 7.8epss 0.32
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,…
- risk 0.53cvss 7.8epss 0.28
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a…
- risk 0.52cvss 9.1epss 0.03
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
- risk 0.52cvss 7.8epss 0.14
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."
- risk 0.51cvss 7.8epss 0.00
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET Framework Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET Framework Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET Framework Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.04
A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially…
Page 2 of 11