.net Framework
by Microsoft
CVEs (207)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1066 | Hig | 0.51 | 7.8 | 0.02 | May 21, 2020 | An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the… | ||
| CVE-2018-8202 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2018 | An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET… | ||
| CVE-2018-1039 | Hig | 0.51 | 7.8 | 0.01 | May 9, 2018 | A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft… | ||
| CVE-2016-3255 | Hig | 0.51 | 7.5 | 0.25 | Jul 13, 2016 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET… | ||
| CVE-2023-36049 | Hig | 0.50 | 7.6 | 0.13 | Nov 14, 2023 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2020-1108 | Hig | 0.50 | 7.5 | 0.12 | May 21, 2020 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. | ||
| CVE-2019-0545 | Hig | 0.50 | 7.5 | 0.10 | Jan 8, 2019 | An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET… | ||
| CVE-2017-8585 | Hig | 0.50 | 7.5 | 0.10 | Jul 11, 2017 | Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability. | ||
| CVE-2016-7270 | Hig | 0.50 | 7.5 | 0.20 | Dec 20, 2016 | The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET… | ||
| CVE-2016-0047 | Hig | 0.50 | 7.5 | 0.21 | Feb 10, 2016 | WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability." | ||
| CVE-2016-0033 | Hig | 0.50 | 7.5 | 0.18 | Feb 10, 2016 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka ".NET Framework Stack Overflow Denial of… | ||
| CVE-2026-50648 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50527 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50525 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-47302 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-23666 | Hig | 0.49 | 7.5 | 0.01 | Apr 14, 2026 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2024-43484 | Hig | 0.49 | 7.5 | 0.03 | Oct 8, 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | ||
| CVE-2024-43483 | Hig | 0.49 | 7.5 | 0.03 | Oct 8, 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | ||
| CVE-2024-21312 | Hig | 0.49 | 7.5 | 0.04 | Jan 9, 2024 | .NET Framework Denial of Service Vulnerability | ||
| CVE-2023-32030 | Hig | 0.49 | 7.5 | 0.02 | Jun 14, 2023 | .NET and Visual Studio Denial of Service Vulnerability |
- risk 0.51cvss 7.8epss 0.02
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET…
- risk 0.51cvss 7.8epss 0.01
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft…
- risk 0.51cvss 7.5epss 0.25
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET…
- risk 0.50cvss 7.6epss 0.13
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
- risk 0.50cvss 7.5epss 0.12
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
- risk 0.50cvss 7.5epss 0.10
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET…
- risk 0.50cvss 7.5epss 0.10
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
- risk 0.50cvss 7.5epss 0.20
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET…
- risk 0.50cvss 7.5epss 0.21
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability."
- risk 0.50cvss 7.5epss 0.18
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka ".NET Framework Stack Overflow Denial of…
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.03
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.04
.NET Framework Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
.NET and Visual Studio Denial of Service Vulnerability
Page 3 of 11